1 /* 2 * This is the new netlink-based wireless configuration interface. 3 * 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net> 5 * Copyright 2013-2014 Intel Mobile Communications GmbH 6 * Copyright 2015-2017 Intel Deutschland GmbH 7 */ 8 9 #include <linux/if.h> 10 #include <linux/module.h> 11 #include <linux/err.h> 12 #include <linux/slab.h> 13 #include <linux/list.h> 14 #include <linux/if_ether.h> 15 #include <linux/ieee80211.h> 16 #include <linux/nl80211.h> 17 #include <linux/rtnetlink.h> 18 #include <linux/netlink.h> 19 #include <linux/etherdevice.h> 20 #include <net/net_namespace.h> 21 #include <net/genetlink.h> 22 #include <net/cfg80211.h> 23 #include <net/sock.h> 24 #include <net/inet_connection_sock.h> 25 #include "core.h" 26 #include "nl80211.h" 27 #include "reg.h" 28 #include "rdev-ops.h" 29 30 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev, 31 struct genl_info *info, 32 struct cfg80211_crypto_settings *settings, 33 int cipher_limit); 34 35 /* the netlink family */ 36 static struct genl_family nl80211_fam; 37 38 /* multicast groups */ 39 enum nl80211_multicast_groups { 40 NL80211_MCGRP_CONFIG, 41 NL80211_MCGRP_SCAN, 42 NL80211_MCGRP_REGULATORY, 43 NL80211_MCGRP_MLME, 44 NL80211_MCGRP_VENDOR, 45 NL80211_MCGRP_NAN, 46 NL80211_MCGRP_TESTMODE /* keep last - ifdef! */ 47 }; 48 49 static const struct genl_multicast_group nl80211_mcgrps[] = { 50 [NL80211_MCGRP_CONFIG] = { .name = NL80211_MULTICAST_GROUP_CONFIG }, 51 [NL80211_MCGRP_SCAN] = { .name = NL80211_MULTICAST_GROUP_SCAN }, 52 [NL80211_MCGRP_REGULATORY] = { .name = NL80211_MULTICAST_GROUP_REG }, 53 [NL80211_MCGRP_MLME] = { .name = NL80211_MULTICAST_GROUP_MLME }, 54 [NL80211_MCGRP_VENDOR] = { .name = NL80211_MULTICAST_GROUP_VENDOR }, 55 [NL80211_MCGRP_NAN] = { .name = NL80211_MULTICAST_GROUP_NAN }, 56 #ifdef CONFIG_NL80211_TESTMODE 57 [NL80211_MCGRP_TESTMODE] = { .name = NL80211_MULTICAST_GROUP_TESTMODE } 58 #endif 59 }; 60 61 /* returns ERR_PTR values */ 62 static struct wireless_dev * 63 __cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs) 64 { 65 struct cfg80211_registered_device *rdev; 66 struct wireless_dev *result = NULL; 67 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX]; 68 bool have_wdev_id = attrs[NL80211_ATTR_WDEV]; 69 u64 wdev_id; 70 int wiphy_idx = -1; 71 int ifidx = -1; 72 73 ASSERT_RTNL(); 74 75 if (!have_ifidx && !have_wdev_id) 76 return ERR_PTR(-EINVAL); 77 78 if (have_ifidx) 79 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]); 80 if (have_wdev_id) { 81 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]); 82 wiphy_idx = wdev_id >> 32; 83 } 84 85 list_for_each_entry(rdev, &cfg80211_rdev_list, list) { 86 struct wireless_dev *wdev; 87 88 if (wiphy_net(&rdev->wiphy) != netns) 89 continue; 90 91 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx) 92 continue; 93 94 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) { 95 if (have_ifidx && wdev->netdev && 96 wdev->netdev->ifindex == ifidx) { 97 result = wdev; 98 break; 99 } 100 if (have_wdev_id && wdev->identifier == (u32)wdev_id) { 101 result = wdev; 102 break; 103 } 104 } 105 106 if (result) 107 break; 108 } 109 110 if (result) 111 return result; 112 return ERR_PTR(-ENODEV); 113 } 114 115 static struct cfg80211_registered_device * 116 __cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs) 117 { 118 struct cfg80211_registered_device *rdev = NULL, *tmp; 119 struct net_device *netdev; 120 121 ASSERT_RTNL(); 122 123 if (!attrs[NL80211_ATTR_WIPHY] && 124 !attrs[NL80211_ATTR_IFINDEX] && 125 !attrs[NL80211_ATTR_WDEV]) 126 return ERR_PTR(-EINVAL); 127 128 if (attrs[NL80211_ATTR_WIPHY]) 129 rdev = cfg80211_rdev_by_wiphy_idx( 130 nla_get_u32(attrs[NL80211_ATTR_WIPHY])); 131 132 if (attrs[NL80211_ATTR_WDEV]) { 133 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]); 134 struct wireless_dev *wdev; 135 bool found = false; 136 137 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32); 138 if (tmp) { 139 /* make sure wdev exists */ 140 list_for_each_entry(wdev, &tmp->wiphy.wdev_list, list) { 141 if (wdev->identifier != (u32)wdev_id) 142 continue; 143 found = true; 144 break; 145 } 146 147 if (!found) 148 tmp = NULL; 149 150 if (rdev && tmp != rdev) 151 return ERR_PTR(-EINVAL); 152 rdev = tmp; 153 } 154 } 155 156 if (attrs[NL80211_ATTR_IFINDEX]) { 157 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]); 158 159 netdev = __dev_get_by_index(netns, ifindex); 160 if (netdev) { 161 if (netdev->ieee80211_ptr) 162 tmp = wiphy_to_rdev( 163 netdev->ieee80211_ptr->wiphy); 164 else 165 tmp = NULL; 166 167 /* not wireless device -- return error */ 168 if (!tmp) 169 return ERR_PTR(-EINVAL); 170 171 /* mismatch -- return error */ 172 if (rdev && tmp != rdev) 173 return ERR_PTR(-EINVAL); 174 175 rdev = tmp; 176 } 177 } 178 179 if (!rdev) 180 return ERR_PTR(-ENODEV); 181 182 if (netns != wiphy_net(&rdev->wiphy)) 183 return ERR_PTR(-ENODEV); 184 185 return rdev; 186 } 187 188 /* 189 * This function returns a pointer to the driver 190 * that the genl_info item that is passed refers to. 191 * 192 * The result of this can be a PTR_ERR and hence must 193 * be checked with IS_ERR() for errors. 194 */ 195 static struct cfg80211_registered_device * 196 cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info) 197 { 198 return __cfg80211_rdev_from_attrs(netns, info->attrs); 199 } 200 201 /* policy for the attributes */ 202 static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = { 203 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 }, 204 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING, 205 .len = 20-1 }, 206 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED }, 207 208 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 }, 209 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 }, 210 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 }, 211 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 }, 212 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 }, 213 214 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 }, 215 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 }, 216 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 }, 217 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 }, 218 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 }, 219 [NL80211_ATTR_WIPHY_DYN_ACK] = { .type = NLA_FLAG }, 220 221 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 }, 222 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 }, 223 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 }, 224 225 [NL80211_ATTR_MAC] = { .len = ETH_ALEN }, 226 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN }, 227 228 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, }, 229 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY, 230 .len = WLAN_MAX_KEY_LEN }, 231 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 }, 232 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 }, 233 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG }, 234 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 }, 235 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 }, 236 237 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 }, 238 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 }, 239 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY, 240 .len = IEEE80211_MAX_DATA_LEN }, 241 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY, 242 .len = IEEE80211_MAX_DATA_LEN }, 243 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 }, 244 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED }, 245 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 }, 246 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY, 247 .len = NL80211_MAX_SUPP_RATES }, 248 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 }, 249 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 }, 250 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ }, 251 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY, 252 .len = IEEE80211_MAX_MESH_ID_LEN }, 253 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 }, 254 255 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 }, 256 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED }, 257 258 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 }, 259 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 }, 260 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 }, 261 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY, 262 .len = NL80211_MAX_SUPP_RATES }, 263 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 }, 264 265 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED }, 266 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG }, 267 268 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN }, 269 270 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 }, 271 [NL80211_ATTR_IE] = { .type = NLA_BINARY, 272 .len = IEEE80211_MAX_DATA_LEN }, 273 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED }, 274 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED }, 275 276 [NL80211_ATTR_SSID] = { .type = NLA_BINARY, 277 .len = IEEE80211_MAX_SSID_LEN }, 278 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 }, 279 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 }, 280 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG }, 281 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG }, 282 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 }, 283 [NL80211_ATTR_STA_FLAGS2] = { 284 .len = sizeof(struct nl80211_sta_flag_update), 285 }, 286 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG }, 287 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 }, 288 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG }, 289 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG }, 290 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 }, 291 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 }, 292 [NL80211_ATTR_PID] = { .type = NLA_U32 }, 293 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 }, 294 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY, 295 .len = WLAN_PMKID_LEN }, 296 [NL80211_ATTR_DURATION] = { .type = NLA_U32 }, 297 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 }, 298 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED }, 299 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY, 300 .len = IEEE80211_MAX_DATA_LEN }, 301 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, }, 302 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 }, 303 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, }, 304 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG }, 305 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 }, 306 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 }, 307 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 }, 308 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 }, 309 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 }, 310 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 }, 311 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 }, 312 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG }, 313 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED }, 314 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED }, 315 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 }, 316 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 }, 317 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED }, 318 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED }, 319 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 }, 320 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY, 321 .len = IEEE80211_MAX_DATA_LEN }, 322 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY, 323 .len = IEEE80211_MAX_DATA_LEN }, 324 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG }, 325 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED }, 326 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG }, 327 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 }, 328 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 }, 329 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 }, 330 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG }, 331 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG }, 332 [NL80211_ATTR_TDLS_INITIATOR] = { .type = NLA_FLAG }, 333 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG }, 334 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY, 335 .len = IEEE80211_MAX_DATA_LEN }, 336 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 }, 337 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG }, 338 [NL80211_ATTR_HT_CAPABILITY_MASK] = { 339 .len = NL80211_HT_CAPABILITY_LEN 340 }, 341 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 }, 342 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 }, 343 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 }, 344 [NL80211_ATTR_WDEV] = { .type = NLA_U64 }, 345 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 }, 346 [NL80211_ATTR_AUTH_DATA] = { .type = NLA_BINARY, }, 347 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN }, 348 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 }, 349 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 }, 350 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 }, 351 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 }, 352 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED }, 353 [NL80211_ATTR_STA_CAPABILITY] = { .type = NLA_U16 }, 354 [NL80211_ATTR_STA_EXT_CAPABILITY] = { .type = NLA_BINARY, }, 355 [NL80211_ATTR_SPLIT_WIPHY_DUMP] = { .type = NLA_FLAG, }, 356 [NL80211_ATTR_DISABLE_VHT] = { .type = NLA_FLAG }, 357 [NL80211_ATTR_VHT_CAPABILITY_MASK] = { 358 .len = NL80211_VHT_CAPABILITY_LEN, 359 }, 360 [NL80211_ATTR_MDID] = { .type = NLA_U16 }, 361 [NL80211_ATTR_IE_RIC] = { .type = NLA_BINARY, 362 .len = IEEE80211_MAX_DATA_LEN }, 363 [NL80211_ATTR_PEER_AID] = { .type = NLA_U16 }, 364 [NL80211_ATTR_CH_SWITCH_COUNT] = { .type = NLA_U32 }, 365 [NL80211_ATTR_CH_SWITCH_BLOCK_TX] = { .type = NLA_FLAG }, 366 [NL80211_ATTR_CSA_IES] = { .type = NLA_NESTED }, 367 [NL80211_ATTR_CSA_C_OFF_BEACON] = { .type = NLA_BINARY }, 368 [NL80211_ATTR_CSA_C_OFF_PRESP] = { .type = NLA_BINARY }, 369 [NL80211_ATTR_STA_SUPPORTED_CHANNELS] = { .type = NLA_BINARY }, 370 [NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES] = { .type = NLA_BINARY }, 371 [NL80211_ATTR_HANDLE_DFS] = { .type = NLA_FLAG }, 372 [NL80211_ATTR_OPMODE_NOTIF] = { .type = NLA_U8 }, 373 [NL80211_ATTR_VENDOR_ID] = { .type = NLA_U32 }, 374 [NL80211_ATTR_VENDOR_SUBCMD] = { .type = NLA_U32 }, 375 [NL80211_ATTR_VENDOR_DATA] = { .type = NLA_BINARY }, 376 [NL80211_ATTR_QOS_MAP] = { .type = NLA_BINARY, 377 .len = IEEE80211_QOS_MAP_LEN_MAX }, 378 [NL80211_ATTR_MAC_HINT] = { .len = ETH_ALEN }, 379 [NL80211_ATTR_WIPHY_FREQ_HINT] = { .type = NLA_U32 }, 380 [NL80211_ATTR_TDLS_PEER_CAPABILITY] = { .type = NLA_U32 }, 381 [NL80211_ATTR_SOCKET_OWNER] = { .type = NLA_FLAG }, 382 [NL80211_ATTR_CSA_C_OFFSETS_TX] = { .type = NLA_BINARY }, 383 [NL80211_ATTR_USE_RRM] = { .type = NLA_FLAG }, 384 [NL80211_ATTR_TSID] = { .type = NLA_U8 }, 385 [NL80211_ATTR_USER_PRIO] = { .type = NLA_U8 }, 386 [NL80211_ATTR_ADMITTED_TIME] = { .type = NLA_U16 }, 387 [NL80211_ATTR_SMPS_MODE] = { .type = NLA_U8 }, 388 [NL80211_ATTR_MAC_MASK] = { .len = ETH_ALEN }, 389 [NL80211_ATTR_WIPHY_SELF_MANAGED_REG] = { .type = NLA_FLAG }, 390 [NL80211_ATTR_NETNS_FD] = { .type = NLA_U32 }, 391 [NL80211_ATTR_SCHED_SCAN_DELAY] = { .type = NLA_U32 }, 392 [NL80211_ATTR_REG_INDOOR] = { .type = NLA_FLAG }, 393 [NL80211_ATTR_PBSS] = { .type = NLA_FLAG }, 394 [NL80211_ATTR_BSS_SELECT] = { .type = NLA_NESTED }, 395 [NL80211_ATTR_STA_SUPPORT_P2P_PS] = { .type = NLA_U8 }, 396 [NL80211_ATTR_MU_MIMO_GROUP_DATA] = { 397 .len = VHT_MUMIMO_GROUPS_DATA_LEN 398 }, 399 [NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR] = { .len = ETH_ALEN }, 400 [NL80211_ATTR_NAN_MASTER_PREF] = { .type = NLA_U8 }, 401 [NL80211_ATTR_BANDS] = { .type = NLA_U32 }, 402 [NL80211_ATTR_NAN_FUNC] = { .type = NLA_NESTED }, 403 [NL80211_ATTR_FILS_KEK] = { .type = NLA_BINARY, 404 .len = FILS_MAX_KEK_LEN }, 405 [NL80211_ATTR_FILS_NONCES] = { .len = 2 * FILS_NONCE_LEN }, 406 [NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED] = { .type = NLA_FLAG, }, 407 [NL80211_ATTR_BSSID] = { .len = ETH_ALEN }, 408 [NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI] = { .type = NLA_S8 }, 409 [NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST] = { 410 .len = sizeof(struct nl80211_bss_select_rssi_adjust) 411 }, 412 [NL80211_ATTR_TIMEOUT_REASON] = { .type = NLA_U32 }, 413 }; 414 415 /* policy for the key attributes */ 416 static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = { 417 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN }, 418 [NL80211_KEY_IDX] = { .type = NLA_U8 }, 419 [NL80211_KEY_CIPHER] = { .type = NLA_U32 }, 420 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 }, 421 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG }, 422 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG }, 423 [NL80211_KEY_TYPE] = { .type = NLA_U32 }, 424 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED }, 425 }; 426 427 /* policy for the key default flags */ 428 static const struct nla_policy 429 nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = { 430 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG }, 431 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG }, 432 }; 433 434 #ifdef CONFIG_PM 435 /* policy for WoWLAN attributes */ 436 static const struct nla_policy 437 nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = { 438 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG }, 439 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG }, 440 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG }, 441 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED }, 442 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG }, 443 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG }, 444 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG }, 445 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG }, 446 [NL80211_WOWLAN_TRIG_TCP_CONNECTION] = { .type = NLA_NESTED }, 447 [NL80211_WOWLAN_TRIG_NET_DETECT] = { .type = NLA_NESTED }, 448 }; 449 450 static const struct nla_policy 451 nl80211_wowlan_tcp_policy[NUM_NL80211_WOWLAN_TCP] = { 452 [NL80211_WOWLAN_TCP_SRC_IPV4] = { .type = NLA_U32 }, 453 [NL80211_WOWLAN_TCP_DST_IPV4] = { .type = NLA_U32 }, 454 [NL80211_WOWLAN_TCP_DST_MAC] = { .len = ETH_ALEN }, 455 [NL80211_WOWLAN_TCP_SRC_PORT] = { .type = NLA_U16 }, 456 [NL80211_WOWLAN_TCP_DST_PORT] = { .type = NLA_U16 }, 457 [NL80211_WOWLAN_TCP_DATA_PAYLOAD] = { .len = 1 }, 458 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ] = { 459 .len = sizeof(struct nl80211_wowlan_tcp_data_seq) 460 }, 461 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN] = { 462 .len = sizeof(struct nl80211_wowlan_tcp_data_token) 463 }, 464 [NL80211_WOWLAN_TCP_DATA_INTERVAL] = { .type = NLA_U32 }, 465 [NL80211_WOWLAN_TCP_WAKE_PAYLOAD] = { .len = 1 }, 466 [NL80211_WOWLAN_TCP_WAKE_MASK] = { .len = 1 }, 467 }; 468 #endif /* CONFIG_PM */ 469 470 /* policy for coalesce rule attributes */ 471 static const struct nla_policy 472 nl80211_coalesce_policy[NUM_NL80211_ATTR_COALESCE_RULE] = { 473 [NL80211_ATTR_COALESCE_RULE_DELAY] = { .type = NLA_U32 }, 474 [NL80211_ATTR_COALESCE_RULE_CONDITION] = { .type = NLA_U32 }, 475 [NL80211_ATTR_COALESCE_RULE_PKT_PATTERN] = { .type = NLA_NESTED }, 476 }; 477 478 /* policy for GTK rekey offload attributes */ 479 static const struct nla_policy 480 nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = { 481 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN }, 482 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN }, 483 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN }, 484 }; 485 486 static const struct nla_policy 487 nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = { 488 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY, 489 .len = IEEE80211_MAX_SSID_LEN }, 490 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 }, 491 }; 492 493 static const struct nla_policy 494 nl80211_plan_policy[NL80211_SCHED_SCAN_PLAN_MAX + 1] = { 495 [NL80211_SCHED_SCAN_PLAN_INTERVAL] = { .type = NLA_U32 }, 496 [NL80211_SCHED_SCAN_PLAN_ITERATIONS] = { .type = NLA_U32 }, 497 }; 498 499 static const struct nla_policy 500 nl80211_bss_select_policy[NL80211_BSS_SELECT_ATTR_MAX + 1] = { 501 [NL80211_BSS_SELECT_ATTR_RSSI] = { .type = NLA_FLAG }, 502 [NL80211_BSS_SELECT_ATTR_BAND_PREF] = { .type = NLA_U32 }, 503 [NL80211_BSS_SELECT_ATTR_RSSI_ADJUST] = { 504 .len = sizeof(struct nl80211_bss_select_rssi_adjust) 505 }, 506 }; 507 508 /* policy for NAN function attributes */ 509 static const struct nla_policy 510 nl80211_nan_func_policy[NL80211_NAN_FUNC_ATTR_MAX + 1] = { 511 [NL80211_NAN_FUNC_TYPE] = { .type = NLA_U8 }, 512 [NL80211_NAN_FUNC_SERVICE_ID] = { .type = NLA_BINARY, 513 .len = NL80211_NAN_FUNC_SERVICE_ID_LEN }, 514 [NL80211_NAN_FUNC_PUBLISH_TYPE] = { .type = NLA_U8 }, 515 [NL80211_NAN_FUNC_PUBLISH_BCAST] = { .type = NLA_FLAG }, 516 [NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE] = { .type = NLA_FLAG }, 517 [NL80211_NAN_FUNC_FOLLOW_UP_ID] = { .type = NLA_U8 }, 518 [NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID] = { .type = NLA_U8 }, 519 [NL80211_NAN_FUNC_FOLLOW_UP_DEST] = { .len = ETH_ALEN }, 520 [NL80211_NAN_FUNC_CLOSE_RANGE] = { .type = NLA_FLAG }, 521 [NL80211_NAN_FUNC_TTL] = { .type = NLA_U32 }, 522 [NL80211_NAN_FUNC_SERVICE_INFO] = { .type = NLA_BINARY, 523 .len = NL80211_NAN_FUNC_SERVICE_SPEC_INFO_MAX_LEN }, 524 [NL80211_NAN_FUNC_SRF] = { .type = NLA_NESTED }, 525 [NL80211_NAN_FUNC_RX_MATCH_FILTER] = { .type = NLA_NESTED }, 526 [NL80211_NAN_FUNC_TX_MATCH_FILTER] = { .type = NLA_NESTED }, 527 [NL80211_NAN_FUNC_INSTANCE_ID] = { .type = NLA_U8 }, 528 [NL80211_NAN_FUNC_TERM_REASON] = { .type = NLA_U8 }, 529 }; 530 531 /* policy for Service Response Filter attributes */ 532 static const struct nla_policy 533 nl80211_nan_srf_policy[NL80211_NAN_SRF_ATTR_MAX + 1] = { 534 [NL80211_NAN_SRF_INCLUDE] = { .type = NLA_FLAG }, 535 [NL80211_NAN_SRF_BF] = { .type = NLA_BINARY, 536 .len = NL80211_NAN_FUNC_SRF_MAX_LEN }, 537 [NL80211_NAN_SRF_BF_IDX] = { .type = NLA_U8 }, 538 [NL80211_NAN_SRF_MAC_ADDRS] = { .type = NLA_NESTED }, 539 }; 540 541 static int nl80211_prepare_wdev_dump(struct sk_buff *skb, 542 struct netlink_callback *cb, 543 struct cfg80211_registered_device **rdev, 544 struct wireless_dev **wdev) 545 { 546 int err; 547 548 if (!cb->args[0]) { 549 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, 550 genl_family_attrbuf(&nl80211_fam), 551 nl80211_fam.maxattr, nl80211_policy); 552 if (err) 553 return err; 554 555 *wdev = __cfg80211_wdev_from_attrs( 556 sock_net(skb->sk), 557 genl_family_attrbuf(&nl80211_fam)); 558 if (IS_ERR(*wdev)) 559 return PTR_ERR(*wdev); 560 *rdev = wiphy_to_rdev((*wdev)->wiphy); 561 /* 0 is the first index - add 1 to parse only once */ 562 cb->args[0] = (*rdev)->wiphy_idx + 1; 563 cb->args[1] = (*wdev)->identifier; 564 } else { 565 /* subtract the 1 again here */ 566 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1); 567 struct wireless_dev *tmp; 568 569 if (!wiphy) 570 return -ENODEV; 571 *rdev = wiphy_to_rdev(wiphy); 572 *wdev = NULL; 573 574 list_for_each_entry(tmp, &(*rdev)->wiphy.wdev_list, list) { 575 if (tmp->identifier == cb->args[1]) { 576 *wdev = tmp; 577 break; 578 } 579 } 580 581 if (!*wdev) 582 return -ENODEV; 583 } 584 585 return 0; 586 } 587 588 /* IE validation */ 589 static bool is_valid_ie_attr(const struct nlattr *attr) 590 { 591 const u8 *pos; 592 int len; 593 594 if (!attr) 595 return true; 596 597 pos = nla_data(attr); 598 len = nla_len(attr); 599 600 while (len) { 601 u8 elemlen; 602 603 if (len < 2) 604 return false; 605 len -= 2; 606 607 elemlen = pos[1]; 608 if (elemlen > len) 609 return false; 610 611 len -= elemlen; 612 pos += 2 + elemlen; 613 } 614 615 return true; 616 } 617 618 /* message building helper */ 619 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq, 620 int flags, u8 cmd) 621 { 622 /* since there is no private header just add the generic one */ 623 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd); 624 } 625 626 static int nl80211_msg_put_channel(struct sk_buff *msg, 627 struct ieee80211_channel *chan, 628 bool large) 629 { 630 /* Some channels must be completely excluded from the 631 * list to protect old user-space tools from breaking 632 */ 633 if (!large && chan->flags & 634 (IEEE80211_CHAN_NO_10MHZ | IEEE80211_CHAN_NO_20MHZ)) 635 return 0; 636 637 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ, 638 chan->center_freq)) 639 goto nla_put_failure; 640 641 if ((chan->flags & IEEE80211_CHAN_DISABLED) && 642 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED)) 643 goto nla_put_failure; 644 if (chan->flags & IEEE80211_CHAN_NO_IR) { 645 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IR)) 646 goto nla_put_failure; 647 if (nla_put_flag(msg, __NL80211_FREQUENCY_ATTR_NO_IBSS)) 648 goto nla_put_failure; 649 } 650 if (chan->flags & IEEE80211_CHAN_RADAR) { 651 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR)) 652 goto nla_put_failure; 653 if (large) { 654 u32 time; 655 656 time = elapsed_jiffies_msecs(chan->dfs_state_entered); 657 658 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_STATE, 659 chan->dfs_state)) 660 goto nla_put_failure; 661 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_TIME, 662 time)) 663 goto nla_put_failure; 664 if (nla_put_u32(msg, 665 NL80211_FREQUENCY_ATTR_DFS_CAC_TIME, 666 chan->dfs_cac_ms)) 667 goto nla_put_failure; 668 } 669 } 670 671 if (large) { 672 if ((chan->flags & IEEE80211_CHAN_NO_HT40MINUS) && 673 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_MINUS)) 674 goto nla_put_failure; 675 if ((chan->flags & IEEE80211_CHAN_NO_HT40PLUS) && 676 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_PLUS)) 677 goto nla_put_failure; 678 if ((chan->flags & IEEE80211_CHAN_NO_80MHZ) && 679 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_80MHZ)) 680 goto nla_put_failure; 681 if ((chan->flags & IEEE80211_CHAN_NO_160MHZ) && 682 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_160MHZ)) 683 goto nla_put_failure; 684 if ((chan->flags & IEEE80211_CHAN_INDOOR_ONLY) && 685 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_INDOOR_ONLY)) 686 goto nla_put_failure; 687 if ((chan->flags & IEEE80211_CHAN_IR_CONCURRENT) && 688 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_IR_CONCURRENT)) 689 goto nla_put_failure; 690 if ((chan->flags & IEEE80211_CHAN_NO_20MHZ) && 691 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_20MHZ)) 692 goto nla_put_failure; 693 if ((chan->flags & IEEE80211_CHAN_NO_10MHZ) && 694 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_10MHZ)) 695 goto nla_put_failure; 696 } 697 698 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER, 699 DBM_TO_MBM(chan->max_power))) 700 goto nla_put_failure; 701 702 return 0; 703 704 nla_put_failure: 705 return -ENOBUFS; 706 } 707 708 /* netlink command implementations */ 709 710 struct key_parse { 711 struct key_params p; 712 int idx; 713 int type; 714 bool def, defmgmt; 715 bool def_uni, def_multi; 716 }; 717 718 static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k) 719 { 720 struct nlattr *tb[NL80211_KEY_MAX + 1]; 721 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key, 722 nl80211_key_policy); 723 if (err) 724 return err; 725 726 k->def = !!tb[NL80211_KEY_DEFAULT]; 727 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT]; 728 729 if (k->def) { 730 k->def_uni = true; 731 k->def_multi = true; 732 } 733 if (k->defmgmt) 734 k->def_multi = true; 735 736 if (tb[NL80211_KEY_IDX]) 737 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]); 738 739 if (tb[NL80211_KEY_DATA]) { 740 k->p.key = nla_data(tb[NL80211_KEY_DATA]); 741 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]); 742 } 743 744 if (tb[NL80211_KEY_SEQ]) { 745 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]); 746 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]); 747 } 748 749 if (tb[NL80211_KEY_CIPHER]) 750 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]); 751 752 if (tb[NL80211_KEY_TYPE]) { 753 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]); 754 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES) 755 return -EINVAL; 756 } 757 758 if (tb[NL80211_KEY_DEFAULT_TYPES]) { 759 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES]; 760 761 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1, 762 tb[NL80211_KEY_DEFAULT_TYPES], 763 nl80211_key_default_policy); 764 if (err) 765 return err; 766 767 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST]; 768 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST]; 769 } 770 771 return 0; 772 } 773 774 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k) 775 { 776 if (info->attrs[NL80211_ATTR_KEY_DATA]) { 777 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]); 778 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]); 779 } 780 781 if (info->attrs[NL80211_ATTR_KEY_SEQ]) { 782 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]); 783 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]); 784 } 785 786 if (info->attrs[NL80211_ATTR_KEY_IDX]) 787 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]); 788 789 if (info->attrs[NL80211_ATTR_KEY_CIPHER]) 790 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]); 791 792 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT]; 793 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT]; 794 795 if (k->def) { 796 k->def_uni = true; 797 k->def_multi = true; 798 } 799 if (k->defmgmt) 800 k->def_multi = true; 801 802 if (info->attrs[NL80211_ATTR_KEY_TYPE]) { 803 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]); 804 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES) 805 return -EINVAL; 806 } 807 808 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) { 809 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES]; 810 int err = nla_parse_nested( 811 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1, 812 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES], 813 nl80211_key_default_policy); 814 if (err) 815 return err; 816 817 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST]; 818 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST]; 819 } 820 821 return 0; 822 } 823 824 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k) 825 { 826 int err; 827 828 memset(k, 0, sizeof(*k)); 829 k->idx = -1; 830 k->type = -1; 831 832 if (info->attrs[NL80211_ATTR_KEY]) 833 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k); 834 else 835 err = nl80211_parse_key_old(info, k); 836 837 if (err) 838 return err; 839 840 if (k->def && k->defmgmt) 841 return -EINVAL; 842 843 if (k->defmgmt) { 844 if (k->def_uni || !k->def_multi) 845 return -EINVAL; 846 } 847 848 if (k->idx != -1) { 849 if (k->defmgmt) { 850 if (k->idx < 4 || k->idx > 5) 851 return -EINVAL; 852 } else if (k->def) { 853 if (k->idx < 0 || k->idx > 3) 854 return -EINVAL; 855 } else { 856 if (k->idx < 0 || k->idx > 5) 857 return -EINVAL; 858 } 859 } 860 861 return 0; 862 } 863 864 static struct cfg80211_cached_keys * 865 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev, 866 struct nlattr *keys, bool *no_ht) 867 { 868 struct key_parse parse; 869 struct nlattr *key; 870 struct cfg80211_cached_keys *result; 871 int rem, err, def = 0; 872 bool have_key = false; 873 874 nla_for_each_nested(key, keys, rem) { 875 have_key = true; 876 break; 877 } 878 879 if (!have_key) 880 return NULL; 881 882 result = kzalloc(sizeof(*result), GFP_KERNEL); 883 if (!result) 884 return ERR_PTR(-ENOMEM); 885 886 result->def = -1; 887 888 nla_for_each_nested(key, keys, rem) { 889 memset(&parse, 0, sizeof(parse)); 890 parse.idx = -1; 891 892 err = nl80211_parse_key_new(key, &parse); 893 if (err) 894 goto error; 895 err = -EINVAL; 896 if (!parse.p.key) 897 goto error; 898 if (parse.idx < 0 || parse.idx > 3) 899 goto error; 900 if (parse.def) { 901 if (def) 902 goto error; 903 def = 1; 904 result->def = parse.idx; 905 if (!parse.def_uni || !parse.def_multi) 906 goto error; 907 } else if (parse.defmgmt) 908 goto error; 909 err = cfg80211_validate_key_settings(rdev, &parse.p, 910 parse.idx, false, NULL); 911 if (err) 912 goto error; 913 if (parse.p.cipher != WLAN_CIPHER_SUITE_WEP40 && 914 parse.p.cipher != WLAN_CIPHER_SUITE_WEP104) { 915 err = -EINVAL; 916 goto error; 917 } 918 result->params[parse.idx].cipher = parse.p.cipher; 919 result->params[parse.idx].key_len = parse.p.key_len; 920 result->params[parse.idx].key = result->data[parse.idx]; 921 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len); 922 923 /* must be WEP key if we got here */ 924 if (no_ht) 925 *no_ht = true; 926 } 927 928 if (result->def < 0) { 929 err = -EINVAL; 930 goto error; 931 } 932 933 return result; 934 error: 935 kfree(result); 936 return ERR_PTR(err); 937 } 938 939 static int nl80211_key_allowed(struct wireless_dev *wdev) 940 { 941 ASSERT_WDEV_LOCK(wdev); 942 943 switch (wdev->iftype) { 944 case NL80211_IFTYPE_AP: 945 case NL80211_IFTYPE_AP_VLAN: 946 case NL80211_IFTYPE_P2P_GO: 947 case NL80211_IFTYPE_MESH_POINT: 948 break; 949 case NL80211_IFTYPE_ADHOC: 950 case NL80211_IFTYPE_STATION: 951 case NL80211_IFTYPE_P2P_CLIENT: 952 if (!wdev->current_bss) 953 return -ENOLINK; 954 break; 955 case NL80211_IFTYPE_UNSPECIFIED: 956 case NL80211_IFTYPE_OCB: 957 case NL80211_IFTYPE_MONITOR: 958 case NL80211_IFTYPE_NAN: 959 case NL80211_IFTYPE_P2P_DEVICE: 960 case NL80211_IFTYPE_WDS: 961 case NUM_NL80211_IFTYPES: 962 return -EINVAL; 963 } 964 965 return 0; 966 } 967 968 static struct ieee80211_channel *nl80211_get_valid_chan(struct wiphy *wiphy, 969 struct nlattr *tb) 970 { 971 struct ieee80211_channel *chan; 972 973 if (tb == NULL) 974 return NULL; 975 chan = ieee80211_get_channel(wiphy, nla_get_u32(tb)); 976 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) 977 return NULL; 978 return chan; 979 } 980 981 static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes) 982 { 983 struct nlattr *nl_modes = nla_nest_start(msg, attr); 984 int i; 985 986 if (!nl_modes) 987 goto nla_put_failure; 988 989 i = 0; 990 while (ifmodes) { 991 if ((ifmodes & 1) && nla_put_flag(msg, i)) 992 goto nla_put_failure; 993 ifmodes >>= 1; 994 i++; 995 } 996 997 nla_nest_end(msg, nl_modes); 998 return 0; 999 1000 nla_put_failure: 1001 return -ENOBUFS; 1002 } 1003 1004 static int nl80211_put_iface_combinations(struct wiphy *wiphy, 1005 struct sk_buff *msg, 1006 bool large) 1007 { 1008 struct nlattr *nl_combis; 1009 int i, j; 1010 1011 nl_combis = nla_nest_start(msg, 1012 NL80211_ATTR_INTERFACE_COMBINATIONS); 1013 if (!nl_combis) 1014 goto nla_put_failure; 1015 1016 for (i = 0; i < wiphy->n_iface_combinations; i++) { 1017 const struct ieee80211_iface_combination *c; 1018 struct nlattr *nl_combi, *nl_limits; 1019 1020 c = &wiphy->iface_combinations[i]; 1021 1022 nl_combi = nla_nest_start(msg, i + 1); 1023 if (!nl_combi) 1024 goto nla_put_failure; 1025 1026 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS); 1027 if (!nl_limits) 1028 goto nla_put_failure; 1029 1030 for (j = 0; j < c->n_limits; j++) { 1031 struct nlattr *nl_limit; 1032 1033 nl_limit = nla_nest_start(msg, j + 1); 1034 if (!nl_limit) 1035 goto nla_put_failure; 1036 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX, 1037 c->limits[j].max)) 1038 goto nla_put_failure; 1039 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES, 1040 c->limits[j].types)) 1041 goto nla_put_failure; 1042 nla_nest_end(msg, nl_limit); 1043 } 1044 1045 nla_nest_end(msg, nl_limits); 1046 1047 if (c->beacon_int_infra_match && 1048 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH)) 1049 goto nla_put_failure; 1050 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS, 1051 c->num_different_channels) || 1052 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM, 1053 c->max_interfaces)) 1054 goto nla_put_failure; 1055 if (large && 1056 (nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS, 1057 c->radar_detect_widths) || 1058 nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_REGIONS, 1059 c->radar_detect_regions))) 1060 goto nla_put_failure; 1061 if (c->beacon_int_min_gcd && 1062 nla_put_u32(msg, NL80211_IFACE_COMB_BI_MIN_GCD, 1063 c->beacon_int_min_gcd)) 1064 goto nla_put_failure; 1065 1066 nla_nest_end(msg, nl_combi); 1067 } 1068 1069 nla_nest_end(msg, nl_combis); 1070 1071 return 0; 1072 nla_put_failure: 1073 return -ENOBUFS; 1074 } 1075 1076 #ifdef CONFIG_PM 1077 static int nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device *rdev, 1078 struct sk_buff *msg) 1079 { 1080 const struct wiphy_wowlan_tcp_support *tcp = rdev->wiphy.wowlan->tcp; 1081 struct nlattr *nl_tcp; 1082 1083 if (!tcp) 1084 return 0; 1085 1086 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION); 1087 if (!nl_tcp) 1088 return -ENOBUFS; 1089 1090 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD, 1091 tcp->data_payload_max)) 1092 return -ENOBUFS; 1093 1094 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD, 1095 tcp->data_payload_max)) 1096 return -ENOBUFS; 1097 1098 if (tcp->seq && nla_put_flag(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ)) 1099 return -ENOBUFS; 1100 1101 if (tcp->tok && nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN, 1102 sizeof(*tcp->tok), tcp->tok)) 1103 return -ENOBUFS; 1104 1105 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL, 1106 tcp->data_interval_max)) 1107 return -ENOBUFS; 1108 1109 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD, 1110 tcp->wake_payload_max)) 1111 return -ENOBUFS; 1112 1113 nla_nest_end(msg, nl_tcp); 1114 return 0; 1115 } 1116 1117 static int nl80211_send_wowlan(struct sk_buff *msg, 1118 struct cfg80211_registered_device *rdev, 1119 bool large) 1120 { 1121 struct nlattr *nl_wowlan; 1122 1123 if (!rdev->wiphy.wowlan) 1124 return 0; 1125 1126 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED); 1127 if (!nl_wowlan) 1128 return -ENOBUFS; 1129 1130 if (((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_ANY) && 1131 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) || 1132 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_DISCONNECT) && 1133 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) || 1134 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT) && 1135 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) || 1136 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) && 1137 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) || 1138 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) && 1139 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) || 1140 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) && 1141 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) || 1142 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) && 1143 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) || 1144 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE) && 1145 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))) 1146 return -ENOBUFS; 1147 1148 if (rdev->wiphy.wowlan->n_patterns) { 1149 struct nl80211_pattern_support pat = { 1150 .max_patterns = rdev->wiphy.wowlan->n_patterns, 1151 .min_pattern_len = rdev->wiphy.wowlan->pattern_min_len, 1152 .max_pattern_len = rdev->wiphy.wowlan->pattern_max_len, 1153 .max_pkt_offset = rdev->wiphy.wowlan->max_pkt_offset, 1154 }; 1155 1156 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN, 1157 sizeof(pat), &pat)) 1158 return -ENOBUFS; 1159 } 1160 1161 if ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_NET_DETECT) && 1162 nla_put_u32(msg, NL80211_WOWLAN_TRIG_NET_DETECT, 1163 rdev->wiphy.wowlan->max_nd_match_sets)) 1164 return -ENOBUFS; 1165 1166 if (large && nl80211_send_wowlan_tcp_caps(rdev, msg)) 1167 return -ENOBUFS; 1168 1169 nla_nest_end(msg, nl_wowlan); 1170 1171 return 0; 1172 } 1173 #endif 1174 1175 static int nl80211_send_coalesce(struct sk_buff *msg, 1176 struct cfg80211_registered_device *rdev) 1177 { 1178 struct nl80211_coalesce_rule_support rule; 1179 1180 if (!rdev->wiphy.coalesce) 1181 return 0; 1182 1183 rule.max_rules = rdev->wiphy.coalesce->n_rules; 1184 rule.max_delay = rdev->wiphy.coalesce->max_delay; 1185 rule.pat.max_patterns = rdev->wiphy.coalesce->n_patterns; 1186 rule.pat.min_pattern_len = rdev->wiphy.coalesce->pattern_min_len; 1187 rule.pat.max_pattern_len = rdev->wiphy.coalesce->pattern_max_len; 1188 rule.pat.max_pkt_offset = rdev->wiphy.coalesce->max_pkt_offset; 1189 1190 if (nla_put(msg, NL80211_ATTR_COALESCE_RULE, sizeof(rule), &rule)) 1191 return -ENOBUFS; 1192 1193 return 0; 1194 } 1195 1196 static int nl80211_send_band_rateinfo(struct sk_buff *msg, 1197 struct ieee80211_supported_band *sband) 1198 { 1199 struct nlattr *nl_rates, *nl_rate; 1200 struct ieee80211_rate *rate; 1201 int i; 1202 1203 /* add HT info */ 1204 if (sband->ht_cap.ht_supported && 1205 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET, 1206 sizeof(sband->ht_cap.mcs), 1207 &sband->ht_cap.mcs) || 1208 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA, 1209 sband->ht_cap.cap) || 1210 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR, 1211 sband->ht_cap.ampdu_factor) || 1212 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY, 1213 sband->ht_cap.ampdu_density))) 1214 return -ENOBUFS; 1215 1216 /* add VHT info */ 1217 if (sband->vht_cap.vht_supported && 1218 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET, 1219 sizeof(sband->vht_cap.vht_mcs), 1220 &sband->vht_cap.vht_mcs) || 1221 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA, 1222 sband->vht_cap.cap))) 1223 return -ENOBUFS; 1224 1225 /* add bitrates */ 1226 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES); 1227 if (!nl_rates) 1228 return -ENOBUFS; 1229 1230 for (i = 0; i < sband->n_bitrates; i++) { 1231 nl_rate = nla_nest_start(msg, i); 1232 if (!nl_rate) 1233 return -ENOBUFS; 1234 1235 rate = &sband->bitrates[i]; 1236 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE, 1237 rate->bitrate)) 1238 return -ENOBUFS; 1239 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) && 1240 nla_put_flag(msg, 1241 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE)) 1242 return -ENOBUFS; 1243 1244 nla_nest_end(msg, nl_rate); 1245 } 1246 1247 nla_nest_end(msg, nl_rates); 1248 1249 return 0; 1250 } 1251 1252 static int 1253 nl80211_send_mgmt_stypes(struct sk_buff *msg, 1254 const struct ieee80211_txrx_stypes *mgmt_stypes) 1255 { 1256 u16 stypes; 1257 struct nlattr *nl_ftypes, *nl_ifs; 1258 enum nl80211_iftype ift; 1259 int i; 1260 1261 if (!mgmt_stypes) 1262 return 0; 1263 1264 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES); 1265 if (!nl_ifs) 1266 return -ENOBUFS; 1267 1268 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) { 1269 nl_ftypes = nla_nest_start(msg, ift); 1270 if (!nl_ftypes) 1271 return -ENOBUFS; 1272 i = 0; 1273 stypes = mgmt_stypes[ift].tx; 1274 while (stypes) { 1275 if ((stypes & 1) && 1276 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE, 1277 (i << 4) | IEEE80211_FTYPE_MGMT)) 1278 return -ENOBUFS; 1279 stypes >>= 1; 1280 i++; 1281 } 1282 nla_nest_end(msg, nl_ftypes); 1283 } 1284 1285 nla_nest_end(msg, nl_ifs); 1286 1287 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES); 1288 if (!nl_ifs) 1289 return -ENOBUFS; 1290 1291 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) { 1292 nl_ftypes = nla_nest_start(msg, ift); 1293 if (!nl_ftypes) 1294 return -ENOBUFS; 1295 i = 0; 1296 stypes = mgmt_stypes[ift].rx; 1297 while (stypes) { 1298 if ((stypes & 1) && 1299 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE, 1300 (i << 4) | IEEE80211_FTYPE_MGMT)) 1301 return -ENOBUFS; 1302 stypes >>= 1; 1303 i++; 1304 } 1305 nla_nest_end(msg, nl_ftypes); 1306 } 1307 nla_nest_end(msg, nl_ifs); 1308 1309 return 0; 1310 } 1311 1312 #define CMD(op, n) \ 1313 do { \ 1314 if (rdev->ops->op) { \ 1315 i++; \ 1316 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \ 1317 goto nla_put_failure; \ 1318 } \ 1319 } while (0) 1320 1321 static int nl80211_add_commands_unsplit(struct cfg80211_registered_device *rdev, 1322 struct sk_buff *msg) 1323 { 1324 int i = 0; 1325 1326 /* 1327 * do *NOT* add anything into this function, new things need to be 1328 * advertised only to new versions of userspace that can deal with 1329 * the split (and they can't possibly care about new features... 1330 */ 1331 CMD(add_virtual_intf, NEW_INTERFACE); 1332 CMD(change_virtual_intf, SET_INTERFACE); 1333 CMD(add_key, NEW_KEY); 1334 CMD(start_ap, START_AP); 1335 CMD(add_station, NEW_STATION); 1336 CMD(add_mpath, NEW_MPATH); 1337 CMD(update_mesh_config, SET_MESH_CONFIG); 1338 CMD(change_bss, SET_BSS); 1339 CMD(auth, AUTHENTICATE); 1340 CMD(assoc, ASSOCIATE); 1341 CMD(deauth, DEAUTHENTICATE); 1342 CMD(disassoc, DISASSOCIATE); 1343 CMD(join_ibss, JOIN_IBSS); 1344 CMD(join_mesh, JOIN_MESH); 1345 CMD(set_pmksa, SET_PMKSA); 1346 CMD(del_pmksa, DEL_PMKSA); 1347 CMD(flush_pmksa, FLUSH_PMKSA); 1348 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) 1349 CMD(remain_on_channel, REMAIN_ON_CHANNEL); 1350 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK); 1351 CMD(mgmt_tx, FRAME); 1352 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL); 1353 if (rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK) { 1354 i++; 1355 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS)) 1356 goto nla_put_failure; 1357 } 1358 if (rdev->ops->set_monitor_channel || rdev->ops->start_ap || 1359 rdev->ops->join_mesh) { 1360 i++; 1361 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL)) 1362 goto nla_put_failure; 1363 } 1364 CMD(set_wds_peer, SET_WDS_PEER); 1365 if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) { 1366 CMD(tdls_mgmt, TDLS_MGMT); 1367 CMD(tdls_oper, TDLS_OPER); 1368 } 1369 if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) 1370 CMD(sched_scan_start, START_SCHED_SCAN); 1371 CMD(probe_client, PROBE_CLIENT); 1372 CMD(set_noack_map, SET_NOACK_MAP); 1373 if (rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) { 1374 i++; 1375 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS)) 1376 goto nla_put_failure; 1377 } 1378 CMD(start_p2p_device, START_P2P_DEVICE); 1379 CMD(set_mcast_rate, SET_MCAST_RATE); 1380 #ifdef CONFIG_NL80211_TESTMODE 1381 CMD(testmode_cmd, TESTMODE); 1382 #endif 1383 1384 if (rdev->ops->connect || rdev->ops->auth) { 1385 i++; 1386 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT)) 1387 goto nla_put_failure; 1388 } 1389 1390 if (rdev->ops->disconnect || rdev->ops->deauth) { 1391 i++; 1392 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT)) 1393 goto nla_put_failure; 1394 } 1395 1396 return i; 1397 nla_put_failure: 1398 return -ENOBUFS; 1399 } 1400 1401 struct nl80211_dump_wiphy_state { 1402 s64 filter_wiphy; 1403 long start; 1404 long split_start, band_start, chan_start, capa_start; 1405 bool split; 1406 }; 1407 1408 static int nl80211_send_wiphy(struct cfg80211_registered_device *rdev, 1409 enum nl80211_commands cmd, 1410 struct sk_buff *msg, u32 portid, u32 seq, 1411 int flags, struct nl80211_dump_wiphy_state *state) 1412 { 1413 void *hdr; 1414 struct nlattr *nl_bands, *nl_band; 1415 struct nlattr *nl_freqs, *nl_freq; 1416 struct nlattr *nl_cmds; 1417 enum nl80211_band band; 1418 struct ieee80211_channel *chan; 1419 int i; 1420 const struct ieee80211_txrx_stypes *mgmt_stypes = 1421 rdev->wiphy.mgmt_stypes; 1422 u32 features; 1423 1424 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 1425 if (!hdr) 1426 return -ENOBUFS; 1427 1428 if (WARN_ON(!state)) 1429 return -EINVAL; 1430 1431 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 1432 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME, 1433 wiphy_name(&rdev->wiphy)) || 1434 nla_put_u32(msg, NL80211_ATTR_GENERATION, 1435 cfg80211_rdev_list_generation)) 1436 goto nla_put_failure; 1437 1438 if (cmd != NL80211_CMD_NEW_WIPHY) 1439 goto finish; 1440 1441 switch (state->split_start) { 1442 case 0: 1443 if (nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT, 1444 rdev->wiphy.retry_short) || 1445 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG, 1446 rdev->wiphy.retry_long) || 1447 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD, 1448 rdev->wiphy.frag_threshold) || 1449 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD, 1450 rdev->wiphy.rts_threshold) || 1451 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS, 1452 rdev->wiphy.coverage_class) || 1453 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS, 1454 rdev->wiphy.max_scan_ssids) || 1455 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS, 1456 rdev->wiphy.max_sched_scan_ssids) || 1457 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN, 1458 rdev->wiphy.max_scan_ie_len) || 1459 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN, 1460 rdev->wiphy.max_sched_scan_ie_len) || 1461 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS, 1462 rdev->wiphy.max_match_sets) || 1463 nla_put_u32(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_PLANS, 1464 rdev->wiphy.max_sched_scan_plans) || 1465 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_INTERVAL, 1466 rdev->wiphy.max_sched_scan_plan_interval) || 1467 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_ITERATIONS, 1468 rdev->wiphy.max_sched_scan_plan_iterations)) 1469 goto nla_put_failure; 1470 1471 if ((rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) && 1472 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN)) 1473 goto nla_put_failure; 1474 if ((rdev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) && 1475 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH)) 1476 goto nla_put_failure; 1477 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) && 1478 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD)) 1479 goto nla_put_failure; 1480 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) && 1481 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT)) 1482 goto nla_put_failure; 1483 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) && 1484 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT)) 1485 goto nla_put_failure; 1486 if ((rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) && 1487 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP)) 1488 goto nla_put_failure; 1489 state->split_start++; 1490 if (state->split) 1491 break; 1492 case 1: 1493 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES, 1494 sizeof(u32) * rdev->wiphy.n_cipher_suites, 1495 rdev->wiphy.cipher_suites)) 1496 goto nla_put_failure; 1497 1498 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS, 1499 rdev->wiphy.max_num_pmkids)) 1500 goto nla_put_failure; 1501 1502 if ((rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) && 1503 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE)) 1504 goto nla_put_failure; 1505 1506 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX, 1507 rdev->wiphy.available_antennas_tx) || 1508 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX, 1509 rdev->wiphy.available_antennas_rx)) 1510 goto nla_put_failure; 1511 1512 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) && 1513 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD, 1514 rdev->wiphy.probe_resp_offload)) 1515 goto nla_put_failure; 1516 1517 if ((rdev->wiphy.available_antennas_tx || 1518 rdev->wiphy.available_antennas_rx) && 1519 rdev->ops->get_antenna) { 1520 u32 tx_ant = 0, rx_ant = 0; 1521 int res; 1522 1523 res = rdev_get_antenna(rdev, &tx_ant, &rx_ant); 1524 if (!res) { 1525 if (nla_put_u32(msg, 1526 NL80211_ATTR_WIPHY_ANTENNA_TX, 1527 tx_ant) || 1528 nla_put_u32(msg, 1529 NL80211_ATTR_WIPHY_ANTENNA_RX, 1530 rx_ant)) 1531 goto nla_put_failure; 1532 } 1533 } 1534 1535 state->split_start++; 1536 if (state->split) 1537 break; 1538 case 2: 1539 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES, 1540 rdev->wiphy.interface_modes)) 1541 goto nla_put_failure; 1542 state->split_start++; 1543 if (state->split) 1544 break; 1545 case 3: 1546 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS); 1547 if (!nl_bands) 1548 goto nla_put_failure; 1549 1550 for (band = state->band_start; 1551 band < NUM_NL80211_BANDS; band++) { 1552 struct ieee80211_supported_band *sband; 1553 1554 sband = rdev->wiphy.bands[band]; 1555 1556 if (!sband) 1557 continue; 1558 1559 nl_band = nla_nest_start(msg, band); 1560 if (!nl_band) 1561 goto nla_put_failure; 1562 1563 switch (state->chan_start) { 1564 case 0: 1565 if (nl80211_send_band_rateinfo(msg, sband)) 1566 goto nla_put_failure; 1567 state->chan_start++; 1568 if (state->split) 1569 break; 1570 default: 1571 /* add frequencies */ 1572 nl_freqs = nla_nest_start( 1573 msg, NL80211_BAND_ATTR_FREQS); 1574 if (!nl_freqs) 1575 goto nla_put_failure; 1576 1577 for (i = state->chan_start - 1; 1578 i < sband->n_channels; 1579 i++) { 1580 nl_freq = nla_nest_start(msg, i); 1581 if (!nl_freq) 1582 goto nla_put_failure; 1583 1584 chan = &sband->channels[i]; 1585 1586 if (nl80211_msg_put_channel( 1587 msg, chan, 1588 state->split)) 1589 goto nla_put_failure; 1590 1591 nla_nest_end(msg, nl_freq); 1592 if (state->split) 1593 break; 1594 } 1595 if (i < sband->n_channels) 1596 state->chan_start = i + 2; 1597 else 1598 state->chan_start = 0; 1599 nla_nest_end(msg, nl_freqs); 1600 } 1601 1602 nla_nest_end(msg, nl_band); 1603 1604 if (state->split) { 1605 /* start again here */ 1606 if (state->chan_start) 1607 band--; 1608 break; 1609 } 1610 } 1611 nla_nest_end(msg, nl_bands); 1612 1613 if (band < NUM_NL80211_BANDS) 1614 state->band_start = band + 1; 1615 else 1616 state->band_start = 0; 1617 1618 /* if bands & channels are done, continue outside */ 1619 if (state->band_start == 0 && state->chan_start == 0) 1620 state->split_start++; 1621 if (state->split) 1622 break; 1623 case 4: 1624 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS); 1625 if (!nl_cmds) 1626 goto nla_put_failure; 1627 1628 i = nl80211_add_commands_unsplit(rdev, msg); 1629 if (i < 0) 1630 goto nla_put_failure; 1631 if (state->split) { 1632 CMD(crit_proto_start, CRIT_PROTOCOL_START); 1633 CMD(crit_proto_stop, CRIT_PROTOCOL_STOP); 1634 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH) 1635 CMD(channel_switch, CHANNEL_SWITCH); 1636 CMD(set_qos_map, SET_QOS_MAP); 1637 if (rdev->wiphy.features & 1638 NL80211_FEATURE_SUPPORTS_WMM_ADMISSION) 1639 CMD(add_tx_ts, ADD_TX_TS); 1640 CMD(set_multicast_to_unicast, SET_MULTICAST_TO_UNICAST); 1641 CMD(update_connect_params, UPDATE_CONNECT_PARAMS); 1642 } 1643 #undef CMD 1644 1645 nla_nest_end(msg, nl_cmds); 1646 state->split_start++; 1647 if (state->split) 1648 break; 1649 case 5: 1650 if (rdev->ops->remain_on_channel && 1651 (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) && 1652 nla_put_u32(msg, 1653 NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION, 1654 rdev->wiphy.max_remain_on_channel_duration)) 1655 goto nla_put_failure; 1656 1657 if ((rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) && 1658 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK)) 1659 goto nla_put_failure; 1660 1661 if (nl80211_send_mgmt_stypes(msg, mgmt_stypes)) 1662 goto nla_put_failure; 1663 state->split_start++; 1664 if (state->split) 1665 break; 1666 case 6: 1667 #ifdef CONFIG_PM 1668 if (nl80211_send_wowlan(msg, rdev, state->split)) 1669 goto nla_put_failure; 1670 state->split_start++; 1671 if (state->split) 1672 break; 1673 #else 1674 state->split_start++; 1675 #endif 1676 case 7: 1677 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES, 1678 rdev->wiphy.software_iftypes)) 1679 goto nla_put_failure; 1680 1681 if (nl80211_put_iface_combinations(&rdev->wiphy, msg, 1682 state->split)) 1683 goto nla_put_failure; 1684 1685 state->split_start++; 1686 if (state->split) 1687 break; 1688 case 8: 1689 if ((rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) && 1690 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME, 1691 rdev->wiphy.ap_sme_capa)) 1692 goto nla_put_failure; 1693 1694 features = rdev->wiphy.features; 1695 /* 1696 * We can only add the per-channel limit information if the 1697 * dump is split, otherwise it makes it too big. Therefore 1698 * only advertise it in that case. 1699 */ 1700 if (state->split) 1701 features |= NL80211_FEATURE_ADVERTISE_CHAN_LIMITS; 1702 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS, features)) 1703 goto nla_put_failure; 1704 1705 if (rdev->wiphy.ht_capa_mod_mask && 1706 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK, 1707 sizeof(*rdev->wiphy.ht_capa_mod_mask), 1708 rdev->wiphy.ht_capa_mod_mask)) 1709 goto nla_put_failure; 1710 1711 if (rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME && 1712 rdev->wiphy.max_acl_mac_addrs && 1713 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX, 1714 rdev->wiphy.max_acl_mac_addrs)) 1715 goto nla_put_failure; 1716 1717 /* 1718 * Any information below this point is only available to 1719 * applications that can deal with it being split. This 1720 * helps ensure that newly added capabilities don't break 1721 * older tools by overrunning their buffers. 1722 * 1723 * We still increment split_start so that in the split 1724 * case we'll continue with more data in the next round, 1725 * but break unconditionally so unsplit data stops here. 1726 */ 1727 state->split_start++; 1728 break; 1729 case 9: 1730 if (rdev->wiphy.extended_capabilities && 1731 (nla_put(msg, NL80211_ATTR_EXT_CAPA, 1732 rdev->wiphy.extended_capabilities_len, 1733 rdev->wiphy.extended_capabilities) || 1734 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK, 1735 rdev->wiphy.extended_capabilities_len, 1736 rdev->wiphy.extended_capabilities_mask))) 1737 goto nla_put_failure; 1738 1739 if (rdev->wiphy.vht_capa_mod_mask && 1740 nla_put(msg, NL80211_ATTR_VHT_CAPABILITY_MASK, 1741 sizeof(*rdev->wiphy.vht_capa_mod_mask), 1742 rdev->wiphy.vht_capa_mod_mask)) 1743 goto nla_put_failure; 1744 1745 state->split_start++; 1746 break; 1747 case 10: 1748 if (nl80211_send_coalesce(msg, rdev)) 1749 goto nla_put_failure; 1750 1751 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ) && 1752 (nla_put_flag(msg, NL80211_ATTR_SUPPORT_5_MHZ) || 1753 nla_put_flag(msg, NL80211_ATTR_SUPPORT_10_MHZ))) 1754 goto nla_put_failure; 1755 1756 if (rdev->wiphy.max_ap_assoc_sta && 1757 nla_put_u32(msg, NL80211_ATTR_MAX_AP_ASSOC_STA, 1758 rdev->wiphy.max_ap_assoc_sta)) 1759 goto nla_put_failure; 1760 1761 state->split_start++; 1762 break; 1763 case 11: 1764 if (rdev->wiphy.n_vendor_commands) { 1765 const struct nl80211_vendor_cmd_info *info; 1766 struct nlattr *nested; 1767 1768 nested = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA); 1769 if (!nested) 1770 goto nla_put_failure; 1771 1772 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) { 1773 info = &rdev->wiphy.vendor_commands[i].info; 1774 if (nla_put(msg, i + 1, sizeof(*info), info)) 1775 goto nla_put_failure; 1776 } 1777 nla_nest_end(msg, nested); 1778 } 1779 1780 if (rdev->wiphy.n_vendor_events) { 1781 const struct nl80211_vendor_cmd_info *info; 1782 struct nlattr *nested; 1783 1784 nested = nla_nest_start(msg, 1785 NL80211_ATTR_VENDOR_EVENTS); 1786 if (!nested) 1787 goto nla_put_failure; 1788 1789 for (i = 0; i < rdev->wiphy.n_vendor_events; i++) { 1790 info = &rdev->wiphy.vendor_events[i]; 1791 if (nla_put(msg, i + 1, sizeof(*info), info)) 1792 goto nla_put_failure; 1793 } 1794 nla_nest_end(msg, nested); 1795 } 1796 state->split_start++; 1797 break; 1798 case 12: 1799 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH && 1800 nla_put_u8(msg, NL80211_ATTR_MAX_CSA_COUNTERS, 1801 rdev->wiphy.max_num_csa_counters)) 1802 goto nla_put_failure; 1803 1804 if (rdev->wiphy.regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED && 1805 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG)) 1806 goto nla_put_failure; 1807 1808 if (nla_put(msg, NL80211_ATTR_EXT_FEATURES, 1809 sizeof(rdev->wiphy.ext_features), 1810 rdev->wiphy.ext_features)) 1811 goto nla_put_failure; 1812 1813 if (rdev->wiphy.bss_select_support) { 1814 struct nlattr *nested; 1815 u32 bss_select_support = rdev->wiphy.bss_select_support; 1816 1817 nested = nla_nest_start(msg, NL80211_ATTR_BSS_SELECT); 1818 if (!nested) 1819 goto nla_put_failure; 1820 1821 i = 0; 1822 while (bss_select_support) { 1823 if ((bss_select_support & 1) && 1824 nla_put_flag(msg, i)) 1825 goto nla_put_failure; 1826 i++; 1827 bss_select_support >>= 1; 1828 } 1829 nla_nest_end(msg, nested); 1830 } 1831 1832 state->split_start++; 1833 break; 1834 case 13: 1835 if (rdev->wiphy.num_iftype_ext_capab && 1836 rdev->wiphy.iftype_ext_capab) { 1837 struct nlattr *nested_ext_capab, *nested; 1838 1839 nested = nla_nest_start(msg, 1840 NL80211_ATTR_IFTYPE_EXT_CAPA); 1841 if (!nested) 1842 goto nla_put_failure; 1843 1844 for (i = state->capa_start; 1845 i < rdev->wiphy.num_iftype_ext_capab; i++) { 1846 const struct wiphy_iftype_ext_capab *capab; 1847 1848 capab = &rdev->wiphy.iftype_ext_capab[i]; 1849 1850 nested_ext_capab = nla_nest_start(msg, i); 1851 if (!nested_ext_capab || 1852 nla_put_u32(msg, NL80211_ATTR_IFTYPE, 1853 capab->iftype) || 1854 nla_put(msg, NL80211_ATTR_EXT_CAPA, 1855 capab->extended_capabilities_len, 1856 capab->extended_capabilities) || 1857 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK, 1858 capab->extended_capabilities_len, 1859 capab->extended_capabilities_mask)) 1860 goto nla_put_failure; 1861 1862 nla_nest_end(msg, nested_ext_capab); 1863 if (state->split) 1864 break; 1865 } 1866 nla_nest_end(msg, nested); 1867 if (i < rdev->wiphy.num_iftype_ext_capab) { 1868 state->capa_start = i + 1; 1869 break; 1870 } 1871 } 1872 1873 if (nla_put_u32(msg, NL80211_ATTR_BANDS, 1874 rdev->wiphy.nan_supported_bands)) 1875 goto nla_put_failure; 1876 1877 /* done */ 1878 state->split_start = 0; 1879 break; 1880 } 1881 finish: 1882 genlmsg_end(msg, hdr); 1883 return 0; 1884 1885 nla_put_failure: 1886 genlmsg_cancel(msg, hdr); 1887 return -EMSGSIZE; 1888 } 1889 1890 static int nl80211_dump_wiphy_parse(struct sk_buff *skb, 1891 struct netlink_callback *cb, 1892 struct nl80211_dump_wiphy_state *state) 1893 { 1894 struct nlattr **tb = genl_family_attrbuf(&nl80211_fam); 1895 int ret = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, 1896 tb, nl80211_fam.maxattr, nl80211_policy); 1897 /* ignore parse errors for backward compatibility */ 1898 if (ret) 1899 return 0; 1900 1901 state->split = tb[NL80211_ATTR_SPLIT_WIPHY_DUMP]; 1902 if (tb[NL80211_ATTR_WIPHY]) 1903 state->filter_wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]); 1904 if (tb[NL80211_ATTR_WDEV]) 1905 state->filter_wiphy = nla_get_u64(tb[NL80211_ATTR_WDEV]) >> 32; 1906 if (tb[NL80211_ATTR_IFINDEX]) { 1907 struct net_device *netdev; 1908 struct cfg80211_registered_device *rdev; 1909 int ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]); 1910 1911 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx); 1912 if (!netdev) 1913 return -ENODEV; 1914 if (netdev->ieee80211_ptr) { 1915 rdev = wiphy_to_rdev( 1916 netdev->ieee80211_ptr->wiphy); 1917 state->filter_wiphy = rdev->wiphy_idx; 1918 } 1919 } 1920 1921 return 0; 1922 } 1923 1924 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb) 1925 { 1926 int idx = 0, ret; 1927 struct nl80211_dump_wiphy_state *state = (void *)cb->args[0]; 1928 struct cfg80211_registered_device *rdev; 1929 1930 rtnl_lock(); 1931 if (!state) { 1932 state = kzalloc(sizeof(*state), GFP_KERNEL); 1933 if (!state) { 1934 rtnl_unlock(); 1935 return -ENOMEM; 1936 } 1937 state->filter_wiphy = -1; 1938 ret = nl80211_dump_wiphy_parse(skb, cb, state); 1939 if (ret) { 1940 kfree(state); 1941 rtnl_unlock(); 1942 return ret; 1943 } 1944 cb->args[0] = (long)state; 1945 } 1946 1947 list_for_each_entry(rdev, &cfg80211_rdev_list, list) { 1948 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk))) 1949 continue; 1950 if (++idx <= state->start) 1951 continue; 1952 if (state->filter_wiphy != -1 && 1953 state->filter_wiphy != rdev->wiphy_idx) 1954 continue; 1955 /* attempt to fit multiple wiphy data chunks into the skb */ 1956 do { 1957 ret = nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY, 1958 skb, 1959 NETLINK_CB(cb->skb).portid, 1960 cb->nlh->nlmsg_seq, 1961 NLM_F_MULTI, state); 1962 if (ret < 0) { 1963 /* 1964 * If sending the wiphy data didn't fit (ENOBUFS 1965 * or EMSGSIZE returned), this SKB is still 1966 * empty (so it's not too big because another 1967 * wiphy dataset is already in the skb) and 1968 * we've not tried to adjust the dump allocation 1969 * yet ... then adjust the alloc size to be 1970 * bigger, and return 1 but with the empty skb. 1971 * This results in an empty message being RX'ed 1972 * in userspace, but that is ignored. 1973 * 1974 * We can then retry with the larger buffer. 1975 */ 1976 if ((ret == -ENOBUFS || ret == -EMSGSIZE) && 1977 !skb->len && !state->split && 1978 cb->min_dump_alloc < 4096) { 1979 cb->min_dump_alloc = 4096; 1980 state->split_start = 0; 1981 rtnl_unlock(); 1982 return 1; 1983 } 1984 idx--; 1985 break; 1986 } 1987 } while (state->split_start > 0); 1988 break; 1989 } 1990 rtnl_unlock(); 1991 1992 state->start = idx; 1993 1994 return skb->len; 1995 } 1996 1997 static int nl80211_dump_wiphy_done(struct netlink_callback *cb) 1998 { 1999 kfree((void *)cb->args[0]); 2000 return 0; 2001 } 2002 2003 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info) 2004 { 2005 struct sk_buff *msg; 2006 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2007 struct nl80211_dump_wiphy_state state = {}; 2008 2009 msg = nlmsg_new(4096, GFP_KERNEL); 2010 if (!msg) 2011 return -ENOMEM; 2012 2013 if (nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY, msg, 2014 info->snd_portid, info->snd_seq, 0, 2015 &state) < 0) { 2016 nlmsg_free(msg); 2017 return -ENOBUFS; 2018 } 2019 2020 return genlmsg_reply(msg, info); 2021 } 2022 2023 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = { 2024 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 }, 2025 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 }, 2026 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 }, 2027 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 }, 2028 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 }, 2029 }; 2030 2031 static int parse_txq_params(struct nlattr *tb[], 2032 struct ieee80211_txq_params *txq_params) 2033 { 2034 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] || 2035 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] || 2036 !tb[NL80211_TXQ_ATTR_AIFS]) 2037 return -EINVAL; 2038 2039 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]); 2040 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]); 2041 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]); 2042 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]); 2043 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]); 2044 2045 if (txq_params->ac >= NL80211_NUM_ACS) 2046 return -EINVAL; 2047 2048 return 0; 2049 } 2050 2051 static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev) 2052 { 2053 /* 2054 * You can only set the channel explicitly for WDS interfaces, 2055 * all others have their channel managed via their respective 2056 * "establish a connection" command (connect, join, ...) 2057 * 2058 * For AP/GO and mesh mode, the channel can be set with the 2059 * channel userspace API, but is only stored and passed to the 2060 * low-level driver when the AP starts or the mesh is joined. 2061 * This is for backward compatibility, userspace can also give 2062 * the channel in the start-ap or join-mesh commands instead. 2063 * 2064 * Monitors are special as they are normally slaved to 2065 * whatever else is going on, so they have their own special 2066 * operation to set the monitor channel if possible. 2067 */ 2068 return !wdev || 2069 wdev->iftype == NL80211_IFTYPE_AP || 2070 wdev->iftype == NL80211_IFTYPE_MESH_POINT || 2071 wdev->iftype == NL80211_IFTYPE_MONITOR || 2072 wdev->iftype == NL80211_IFTYPE_P2P_GO; 2073 } 2074 2075 static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev, 2076 struct genl_info *info, 2077 struct cfg80211_chan_def *chandef) 2078 { 2079 u32 control_freq; 2080 2081 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ]) 2082 return -EINVAL; 2083 2084 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]); 2085 2086 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq); 2087 chandef->width = NL80211_CHAN_WIDTH_20_NOHT; 2088 chandef->center_freq1 = control_freq; 2089 chandef->center_freq2 = 0; 2090 2091 /* Primary channel not allowed */ 2092 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED) 2093 return -EINVAL; 2094 2095 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) { 2096 enum nl80211_channel_type chantype; 2097 2098 chantype = nla_get_u32( 2099 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]); 2100 2101 switch (chantype) { 2102 case NL80211_CHAN_NO_HT: 2103 case NL80211_CHAN_HT20: 2104 case NL80211_CHAN_HT40PLUS: 2105 case NL80211_CHAN_HT40MINUS: 2106 cfg80211_chandef_create(chandef, chandef->chan, 2107 chantype); 2108 break; 2109 default: 2110 return -EINVAL; 2111 } 2112 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) { 2113 chandef->width = 2114 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]); 2115 if (info->attrs[NL80211_ATTR_CENTER_FREQ1]) 2116 chandef->center_freq1 = 2117 nla_get_u32( 2118 info->attrs[NL80211_ATTR_CENTER_FREQ1]); 2119 if (info->attrs[NL80211_ATTR_CENTER_FREQ2]) 2120 chandef->center_freq2 = 2121 nla_get_u32( 2122 info->attrs[NL80211_ATTR_CENTER_FREQ2]); 2123 } 2124 2125 if (!cfg80211_chandef_valid(chandef)) 2126 return -EINVAL; 2127 2128 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef, 2129 IEEE80211_CHAN_DISABLED)) 2130 return -EINVAL; 2131 2132 if ((chandef->width == NL80211_CHAN_WIDTH_5 || 2133 chandef->width == NL80211_CHAN_WIDTH_10) && 2134 !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ)) 2135 return -EINVAL; 2136 2137 return 0; 2138 } 2139 2140 static int __nl80211_set_channel(struct cfg80211_registered_device *rdev, 2141 struct net_device *dev, 2142 struct genl_info *info) 2143 { 2144 struct cfg80211_chan_def chandef; 2145 int result; 2146 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR; 2147 struct wireless_dev *wdev = NULL; 2148 2149 if (dev) 2150 wdev = dev->ieee80211_ptr; 2151 if (!nl80211_can_set_dev_channel(wdev)) 2152 return -EOPNOTSUPP; 2153 if (wdev) 2154 iftype = wdev->iftype; 2155 2156 result = nl80211_parse_chandef(rdev, info, &chandef); 2157 if (result) 2158 return result; 2159 2160 switch (iftype) { 2161 case NL80211_IFTYPE_AP: 2162 case NL80211_IFTYPE_P2P_GO: 2163 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef, 2164 iftype)) { 2165 result = -EINVAL; 2166 break; 2167 } 2168 if (wdev->beacon_interval) { 2169 if (!dev || !rdev->ops->set_ap_chanwidth || 2170 !(rdev->wiphy.features & 2171 NL80211_FEATURE_AP_MODE_CHAN_WIDTH_CHANGE)) { 2172 result = -EBUSY; 2173 break; 2174 } 2175 2176 /* Only allow dynamic channel width changes */ 2177 if (chandef.chan != wdev->preset_chandef.chan) { 2178 result = -EBUSY; 2179 break; 2180 } 2181 result = rdev_set_ap_chanwidth(rdev, dev, &chandef); 2182 if (result) 2183 break; 2184 } 2185 wdev->preset_chandef = chandef; 2186 result = 0; 2187 break; 2188 case NL80211_IFTYPE_MESH_POINT: 2189 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef); 2190 break; 2191 case NL80211_IFTYPE_MONITOR: 2192 result = cfg80211_set_monitor_channel(rdev, &chandef); 2193 break; 2194 default: 2195 result = -EINVAL; 2196 } 2197 2198 return result; 2199 } 2200 2201 static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info) 2202 { 2203 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2204 struct net_device *netdev = info->user_ptr[1]; 2205 2206 return __nl80211_set_channel(rdev, netdev, info); 2207 } 2208 2209 static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info) 2210 { 2211 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2212 struct net_device *dev = info->user_ptr[1]; 2213 struct wireless_dev *wdev = dev->ieee80211_ptr; 2214 const u8 *bssid; 2215 2216 if (!info->attrs[NL80211_ATTR_MAC]) 2217 return -EINVAL; 2218 2219 if (netif_running(dev)) 2220 return -EBUSY; 2221 2222 if (!rdev->ops->set_wds_peer) 2223 return -EOPNOTSUPP; 2224 2225 if (wdev->iftype != NL80211_IFTYPE_WDS) 2226 return -EOPNOTSUPP; 2227 2228 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 2229 return rdev_set_wds_peer(rdev, dev, bssid); 2230 } 2231 2232 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info) 2233 { 2234 struct cfg80211_registered_device *rdev; 2235 struct net_device *netdev = NULL; 2236 struct wireless_dev *wdev; 2237 int result = 0, rem_txq_params = 0; 2238 struct nlattr *nl_txq_params; 2239 u32 changed; 2240 u8 retry_short = 0, retry_long = 0; 2241 u32 frag_threshold = 0, rts_threshold = 0; 2242 u8 coverage_class = 0; 2243 2244 ASSERT_RTNL(); 2245 2246 /* 2247 * Try to find the wiphy and netdev. Normally this 2248 * function shouldn't need the netdev, but this is 2249 * done for backward compatibility -- previously 2250 * setting the channel was done per wiphy, but now 2251 * it is per netdev. Previous userland like hostapd 2252 * also passed a netdev to set_wiphy, so that it is 2253 * possible to let that go to the right netdev! 2254 */ 2255 2256 if (info->attrs[NL80211_ATTR_IFINDEX]) { 2257 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]); 2258 2259 netdev = __dev_get_by_index(genl_info_net(info), ifindex); 2260 if (netdev && netdev->ieee80211_ptr) 2261 rdev = wiphy_to_rdev(netdev->ieee80211_ptr->wiphy); 2262 else 2263 netdev = NULL; 2264 } 2265 2266 if (!netdev) { 2267 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info), 2268 info->attrs); 2269 if (IS_ERR(rdev)) 2270 return PTR_ERR(rdev); 2271 wdev = NULL; 2272 netdev = NULL; 2273 result = 0; 2274 } else 2275 wdev = netdev->ieee80211_ptr; 2276 2277 /* 2278 * end workaround code, by now the rdev is available 2279 * and locked, and wdev may or may not be NULL. 2280 */ 2281 2282 if (info->attrs[NL80211_ATTR_WIPHY_NAME]) 2283 result = cfg80211_dev_rename( 2284 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME])); 2285 2286 if (result) 2287 return result; 2288 2289 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) { 2290 struct ieee80211_txq_params txq_params; 2291 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1]; 2292 2293 if (!rdev->ops->set_txq_params) 2294 return -EOPNOTSUPP; 2295 2296 if (!netdev) 2297 return -EINVAL; 2298 2299 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 2300 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 2301 return -EINVAL; 2302 2303 if (!netif_running(netdev)) 2304 return -ENETDOWN; 2305 2306 nla_for_each_nested(nl_txq_params, 2307 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS], 2308 rem_txq_params) { 2309 result = nla_parse_nested(tb, NL80211_TXQ_ATTR_MAX, 2310 nl_txq_params, 2311 txq_params_policy); 2312 if (result) 2313 return result; 2314 result = parse_txq_params(tb, &txq_params); 2315 if (result) 2316 return result; 2317 2318 result = rdev_set_txq_params(rdev, netdev, 2319 &txq_params); 2320 if (result) 2321 return result; 2322 } 2323 } 2324 2325 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 2326 result = __nl80211_set_channel( 2327 rdev, 2328 nl80211_can_set_dev_channel(wdev) ? netdev : NULL, 2329 info); 2330 if (result) 2331 return result; 2332 } 2333 2334 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) { 2335 struct wireless_dev *txp_wdev = wdev; 2336 enum nl80211_tx_power_setting type; 2337 int idx, mbm = 0; 2338 2339 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER)) 2340 txp_wdev = NULL; 2341 2342 if (!rdev->ops->set_tx_power) 2343 return -EOPNOTSUPP; 2344 2345 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING; 2346 type = nla_get_u32(info->attrs[idx]); 2347 2348 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] && 2349 (type != NL80211_TX_POWER_AUTOMATIC)) 2350 return -EINVAL; 2351 2352 if (type != NL80211_TX_POWER_AUTOMATIC) { 2353 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL; 2354 mbm = nla_get_u32(info->attrs[idx]); 2355 } 2356 2357 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm); 2358 if (result) 2359 return result; 2360 } 2361 2362 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] && 2363 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) { 2364 u32 tx_ant, rx_ant; 2365 2366 if ((!rdev->wiphy.available_antennas_tx && 2367 !rdev->wiphy.available_antennas_rx) || 2368 !rdev->ops->set_antenna) 2369 return -EOPNOTSUPP; 2370 2371 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]); 2372 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]); 2373 2374 /* reject antenna configurations which don't match the 2375 * available antenna masks, except for the "all" mask */ 2376 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) || 2377 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) 2378 return -EINVAL; 2379 2380 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx; 2381 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx; 2382 2383 result = rdev_set_antenna(rdev, tx_ant, rx_ant); 2384 if (result) 2385 return result; 2386 } 2387 2388 changed = 0; 2389 2390 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) { 2391 retry_short = nla_get_u8( 2392 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]); 2393 if (retry_short == 0) 2394 return -EINVAL; 2395 2396 changed |= WIPHY_PARAM_RETRY_SHORT; 2397 } 2398 2399 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) { 2400 retry_long = nla_get_u8( 2401 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]); 2402 if (retry_long == 0) 2403 return -EINVAL; 2404 2405 changed |= WIPHY_PARAM_RETRY_LONG; 2406 } 2407 2408 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) { 2409 frag_threshold = nla_get_u32( 2410 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]); 2411 if (frag_threshold < 256) 2412 return -EINVAL; 2413 2414 if (frag_threshold != (u32) -1) { 2415 /* 2416 * Fragments (apart from the last one) are required to 2417 * have even length. Make the fragmentation code 2418 * simpler by stripping LSB should someone try to use 2419 * odd threshold value. 2420 */ 2421 frag_threshold &= ~0x1; 2422 } 2423 changed |= WIPHY_PARAM_FRAG_THRESHOLD; 2424 } 2425 2426 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) { 2427 rts_threshold = nla_get_u32( 2428 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]); 2429 changed |= WIPHY_PARAM_RTS_THRESHOLD; 2430 } 2431 2432 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) { 2433 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK]) 2434 return -EINVAL; 2435 2436 coverage_class = nla_get_u8( 2437 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]); 2438 changed |= WIPHY_PARAM_COVERAGE_CLASS; 2439 } 2440 2441 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK]) { 2442 if (!(rdev->wiphy.features & NL80211_FEATURE_ACKTO_ESTIMATION)) 2443 return -EOPNOTSUPP; 2444 2445 changed |= WIPHY_PARAM_DYN_ACK; 2446 } 2447 2448 if (changed) { 2449 u8 old_retry_short, old_retry_long; 2450 u32 old_frag_threshold, old_rts_threshold; 2451 u8 old_coverage_class; 2452 2453 if (!rdev->ops->set_wiphy_params) 2454 return -EOPNOTSUPP; 2455 2456 old_retry_short = rdev->wiphy.retry_short; 2457 old_retry_long = rdev->wiphy.retry_long; 2458 old_frag_threshold = rdev->wiphy.frag_threshold; 2459 old_rts_threshold = rdev->wiphy.rts_threshold; 2460 old_coverage_class = rdev->wiphy.coverage_class; 2461 2462 if (changed & WIPHY_PARAM_RETRY_SHORT) 2463 rdev->wiphy.retry_short = retry_short; 2464 if (changed & WIPHY_PARAM_RETRY_LONG) 2465 rdev->wiphy.retry_long = retry_long; 2466 if (changed & WIPHY_PARAM_FRAG_THRESHOLD) 2467 rdev->wiphy.frag_threshold = frag_threshold; 2468 if (changed & WIPHY_PARAM_RTS_THRESHOLD) 2469 rdev->wiphy.rts_threshold = rts_threshold; 2470 if (changed & WIPHY_PARAM_COVERAGE_CLASS) 2471 rdev->wiphy.coverage_class = coverage_class; 2472 2473 result = rdev_set_wiphy_params(rdev, changed); 2474 if (result) { 2475 rdev->wiphy.retry_short = old_retry_short; 2476 rdev->wiphy.retry_long = old_retry_long; 2477 rdev->wiphy.frag_threshold = old_frag_threshold; 2478 rdev->wiphy.rts_threshold = old_rts_threshold; 2479 rdev->wiphy.coverage_class = old_coverage_class; 2480 return result; 2481 } 2482 } 2483 return 0; 2484 } 2485 2486 static inline u64 wdev_id(struct wireless_dev *wdev) 2487 { 2488 return (u64)wdev->identifier | 2489 ((u64)wiphy_to_rdev(wdev->wiphy)->wiphy_idx << 32); 2490 } 2491 2492 static int nl80211_send_chandef(struct sk_buff *msg, 2493 const struct cfg80211_chan_def *chandef) 2494 { 2495 if (WARN_ON(!cfg80211_chandef_valid(chandef))) 2496 return -EINVAL; 2497 2498 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, 2499 chandef->chan->center_freq)) 2500 return -ENOBUFS; 2501 switch (chandef->width) { 2502 case NL80211_CHAN_WIDTH_20_NOHT: 2503 case NL80211_CHAN_WIDTH_20: 2504 case NL80211_CHAN_WIDTH_40: 2505 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, 2506 cfg80211_get_chandef_type(chandef))) 2507 return -ENOBUFS; 2508 break; 2509 default: 2510 break; 2511 } 2512 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width)) 2513 return -ENOBUFS; 2514 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1)) 2515 return -ENOBUFS; 2516 if (chandef->center_freq2 && 2517 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2)) 2518 return -ENOBUFS; 2519 return 0; 2520 } 2521 2522 static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags, 2523 struct cfg80211_registered_device *rdev, 2524 struct wireless_dev *wdev, bool removal) 2525 { 2526 struct net_device *dev = wdev->netdev; 2527 u8 cmd = NL80211_CMD_NEW_INTERFACE; 2528 void *hdr; 2529 2530 if (removal) 2531 cmd = NL80211_CMD_DEL_INTERFACE; 2532 2533 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 2534 if (!hdr) 2535 return -1; 2536 2537 if (dev && 2538 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 2539 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name))) 2540 goto nla_put_failure; 2541 2542 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 2543 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) || 2544 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 2545 NL80211_ATTR_PAD) || 2546 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) || 2547 nla_put_u32(msg, NL80211_ATTR_GENERATION, 2548 rdev->devlist_generation ^ 2549 (cfg80211_rdev_list_generation << 2))) 2550 goto nla_put_failure; 2551 2552 if (rdev->ops->get_channel) { 2553 int ret; 2554 struct cfg80211_chan_def chandef; 2555 2556 ret = rdev_get_channel(rdev, wdev, &chandef); 2557 if (ret == 0) { 2558 if (nl80211_send_chandef(msg, &chandef)) 2559 goto nla_put_failure; 2560 } 2561 } 2562 2563 if (rdev->ops->get_tx_power) { 2564 int dbm, ret; 2565 2566 ret = rdev_get_tx_power(rdev, wdev, &dbm); 2567 if (ret == 0 && 2568 nla_put_u32(msg, NL80211_ATTR_WIPHY_TX_POWER_LEVEL, 2569 DBM_TO_MBM(dbm))) 2570 goto nla_put_failure; 2571 } 2572 2573 if (wdev->ssid_len) { 2574 if (nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid)) 2575 goto nla_put_failure; 2576 } 2577 2578 genlmsg_end(msg, hdr); 2579 return 0; 2580 2581 nla_put_failure: 2582 genlmsg_cancel(msg, hdr); 2583 return -EMSGSIZE; 2584 } 2585 2586 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb) 2587 { 2588 int wp_idx = 0; 2589 int if_idx = 0; 2590 int wp_start = cb->args[0]; 2591 int if_start = cb->args[1]; 2592 int filter_wiphy = -1; 2593 struct cfg80211_registered_device *rdev; 2594 struct wireless_dev *wdev; 2595 int ret; 2596 2597 rtnl_lock(); 2598 if (!cb->args[2]) { 2599 struct nl80211_dump_wiphy_state state = { 2600 .filter_wiphy = -1, 2601 }; 2602 2603 ret = nl80211_dump_wiphy_parse(skb, cb, &state); 2604 if (ret) 2605 goto out_unlock; 2606 2607 filter_wiphy = state.filter_wiphy; 2608 2609 /* 2610 * if filtering, set cb->args[2] to +1 since 0 is the default 2611 * value needed to determine that parsing is necessary. 2612 */ 2613 if (filter_wiphy >= 0) 2614 cb->args[2] = filter_wiphy + 1; 2615 else 2616 cb->args[2] = -1; 2617 } else if (cb->args[2] > 0) { 2618 filter_wiphy = cb->args[2] - 1; 2619 } 2620 2621 list_for_each_entry(rdev, &cfg80211_rdev_list, list) { 2622 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk))) 2623 continue; 2624 if (wp_idx < wp_start) { 2625 wp_idx++; 2626 continue; 2627 } 2628 2629 if (filter_wiphy >= 0 && filter_wiphy != rdev->wiphy_idx) 2630 continue; 2631 2632 if_idx = 0; 2633 2634 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) { 2635 if (if_idx < if_start) { 2636 if_idx++; 2637 continue; 2638 } 2639 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid, 2640 cb->nlh->nlmsg_seq, NLM_F_MULTI, 2641 rdev, wdev, false) < 0) { 2642 goto out; 2643 } 2644 if_idx++; 2645 } 2646 2647 wp_idx++; 2648 } 2649 out: 2650 cb->args[0] = wp_idx; 2651 cb->args[1] = if_idx; 2652 2653 ret = skb->len; 2654 out_unlock: 2655 rtnl_unlock(); 2656 2657 return ret; 2658 } 2659 2660 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info) 2661 { 2662 struct sk_buff *msg; 2663 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2664 struct wireless_dev *wdev = info->user_ptr[1]; 2665 2666 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 2667 if (!msg) 2668 return -ENOMEM; 2669 2670 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0, 2671 rdev, wdev, false) < 0) { 2672 nlmsg_free(msg); 2673 return -ENOBUFS; 2674 } 2675 2676 return genlmsg_reply(msg, info); 2677 } 2678 2679 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = { 2680 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG }, 2681 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG }, 2682 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG }, 2683 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG }, 2684 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG }, 2685 [NL80211_MNTR_FLAG_ACTIVE] = { .type = NLA_FLAG }, 2686 }; 2687 2688 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags) 2689 { 2690 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1]; 2691 int flag; 2692 2693 *mntrflags = 0; 2694 2695 if (!nla) 2696 return -EINVAL; 2697 2698 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX, 2699 nla, mntr_flags_policy)) 2700 return -EINVAL; 2701 2702 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++) 2703 if (flags[flag]) 2704 *mntrflags |= (1<<flag); 2705 2706 return 0; 2707 } 2708 2709 static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev, 2710 struct net_device *netdev, u8 use_4addr, 2711 enum nl80211_iftype iftype) 2712 { 2713 if (!use_4addr) { 2714 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT)) 2715 return -EBUSY; 2716 return 0; 2717 } 2718 2719 switch (iftype) { 2720 case NL80211_IFTYPE_AP_VLAN: 2721 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP) 2722 return 0; 2723 break; 2724 case NL80211_IFTYPE_STATION: 2725 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION) 2726 return 0; 2727 break; 2728 default: 2729 break; 2730 } 2731 2732 return -EOPNOTSUPP; 2733 } 2734 2735 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info) 2736 { 2737 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2738 struct vif_params params; 2739 int err; 2740 enum nl80211_iftype otype, ntype; 2741 struct net_device *dev = info->user_ptr[1]; 2742 u32 _flags, *flags = NULL; 2743 bool change = false; 2744 2745 memset(¶ms, 0, sizeof(params)); 2746 2747 otype = ntype = dev->ieee80211_ptr->iftype; 2748 2749 if (info->attrs[NL80211_ATTR_IFTYPE]) { 2750 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]); 2751 if (otype != ntype) 2752 change = true; 2753 if (ntype > NL80211_IFTYPE_MAX) 2754 return -EINVAL; 2755 } 2756 2757 if (info->attrs[NL80211_ATTR_MESH_ID]) { 2758 struct wireless_dev *wdev = dev->ieee80211_ptr; 2759 2760 if (ntype != NL80211_IFTYPE_MESH_POINT) 2761 return -EINVAL; 2762 if (netif_running(dev)) 2763 return -EBUSY; 2764 2765 wdev_lock(wdev); 2766 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN != 2767 IEEE80211_MAX_MESH_ID_LEN); 2768 wdev->mesh_id_up_len = 2769 nla_len(info->attrs[NL80211_ATTR_MESH_ID]); 2770 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]), 2771 wdev->mesh_id_up_len); 2772 wdev_unlock(wdev); 2773 } 2774 2775 if (info->attrs[NL80211_ATTR_4ADDR]) { 2776 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]); 2777 change = true; 2778 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype); 2779 if (err) 2780 return err; 2781 } else { 2782 params.use_4addr = -1; 2783 } 2784 2785 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) { 2786 if (ntype != NL80211_IFTYPE_MONITOR) 2787 return -EINVAL; 2788 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS], 2789 &_flags); 2790 if (err) 2791 return err; 2792 2793 flags = &_flags; 2794 change = true; 2795 } 2796 2797 if (info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]) { 2798 const u8 *mumimo_groups; 2799 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER; 2800 2801 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag)) 2802 return -EOPNOTSUPP; 2803 2804 mumimo_groups = 2805 nla_data(info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]); 2806 2807 /* bits 0 and 63 are reserved and must be zero */ 2808 if ((mumimo_groups[0] & BIT(7)) || 2809 (mumimo_groups[VHT_MUMIMO_GROUPS_DATA_LEN - 1] & BIT(0))) 2810 return -EINVAL; 2811 2812 memcpy(params.vht_mumimo_groups, mumimo_groups, 2813 VHT_MUMIMO_GROUPS_DATA_LEN); 2814 change = true; 2815 } 2816 2817 if (info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR]) { 2818 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER; 2819 2820 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag)) 2821 return -EOPNOTSUPP; 2822 2823 nla_memcpy(params.macaddr, 2824 info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR], 2825 ETH_ALEN); 2826 change = true; 2827 } 2828 2829 if (flags && (*flags & MONITOR_FLAG_ACTIVE) && 2830 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR)) 2831 return -EOPNOTSUPP; 2832 2833 if (change) 2834 err = cfg80211_change_iface(rdev, dev, ntype, flags, ¶ms); 2835 else 2836 err = 0; 2837 2838 if (!err && params.use_4addr != -1) 2839 dev->ieee80211_ptr->use_4addr = params.use_4addr; 2840 2841 return err; 2842 } 2843 2844 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info) 2845 { 2846 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2847 struct vif_params params; 2848 struct wireless_dev *wdev; 2849 struct sk_buff *msg; 2850 int err; 2851 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED; 2852 u32 flags; 2853 2854 /* to avoid failing a new interface creation due to pending removal */ 2855 cfg80211_destroy_ifaces(rdev); 2856 2857 memset(¶ms, 0, sizeof(params)); 2858 2859 if (!info->attrs[NL80211_ATTR_IFNAME]) 2860 return -EINVAL; 2861 2862 if (info->attrs[NL80211_ATTR_IFTYPE]) { 2863 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]); 2864 if (type > NL80211_IFTYPE_MAX) 2865 return -EINVAL; 2866 } 2867 2868 if (!rdev->ops->add_virtual_intf || 2869 !(rdev->wiphy.interface_modes & (1 << type))) 2870 return -EOPNOTSUPP; 2871 2872 if ((type == NL80211_IFTYPE_P2P_DEVICE || type == NL80211_IFTYPE_NAN || 2873 rdev->wiphy.features & NL80211_FEATURE_MAC_ON_CREATE) && 2874 info->attrs[NL80211_ATTR_MAC]) { 2875 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC], 2876 ETH_ALEN); 2877 if (!is_valid_ether_addr(params.macaddr)) 2878 return -EADDRNOTAVAIL; 2879 } 2880 2881 if (info->attrs[NL80211_ATTR_4ADDR]) { 2882 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]); 2883 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type); 2884 if (err) 2885 return err; 2886 } 2887 2888 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ? 2889 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL, 2890 &flags); 2891 2892 if (!err && (flags & MONITOR_FLAG_ACTIVE) && 2893 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR)) 2894 return -EOPNOTSUPP; 2895 2896 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 2897 if (!msg) 2898 return -ENOMEM; 2899 2900 wdev = rdev_add_virtual_intf(rdev, 2901 nla_data(info->attrs[NL80211_ATTR_IFNAME]), 2902 NET_NAME_USER, type, err ? NULL : &flags, 2903 ¶ms); 2904 if (WARN_ON(!wdev)) { 2905 nlmsg_free(msg); 2906 return -EPROTO; 2907 } else if (IS_ERR(wdev)) { 2908 nlmsg_free(msg); 2909 return PTR_ERR(wdev); 2910 } 2911 2912 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) 2913 wdev->owner_nlportid = info->snd_portid; 2914 2915 switch (type) { 2916 case NL80211_IFTYPE_MESH_POINT: 2917 if (!info->attrs[NL80211_ATTR_MESH_ID]) 2918 break; 2919 wdev_lock(wdev); 2920 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN != 2921 IEEE80211_MAX_MESH_ID_LEN); 2922 wdev->mesh_id_up_len = 2923 nla_len(info->attrs[NL80211_ATTR_MESH_ID]); 2924 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]), 2925 wdev->mesh_id_up_len); 2926 wdev_unlock(wdev); 2927 break; 2928 case NL80211_IFTYPE_NAN: 2929 case NL80211_IFTYPE_P2P_DEVICE: 2930 /* 2931 * P2P Device and NAN do not have a netdev, so don't go 2932 * through the netdev notifier and must be added here 2933 */ 2934 mutex_init(&wdev->mtx); 2935 INIT_LIST_HEAD(&wdev->event_list); 2936 spin_lock_init(&wdev->event_lock); 2937 INIT_LIST_HEAD(&wdev->mgmt_registrations); 2938 spin_lock_init(&wdev->mgmt_registrations_lock); 2939 2940 wdev->identifier = ++rdev->wdev_id; 2941 list_add_rcu(&wdev->list, &rdev->wiphy.wdev_list); 2942 rdev->devlist_generation++; 2943 break; 2944 default: 2945 break; 2946 } 2947 2948 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0, 2949 rdev, wdev, false) < 0) { 2950 nlmsg_free(msg); 2951 return -ENOBUFS; 2952 } 2953 2954 /* 2955 * For wdevs which have no associated netdev object (e.g. of type 2956 * NL80211_IFTYPE_P2P_DEVICE), emit the NEW_INTERFACE event here. 2957 * For all other types, the event will be generated from the 2958 * netdev notifier 2959 */ 2960 if (!wdev->netdev) 2961 nl80211_notify_iface(rdev, wdev, NL80211_CMD_NEW_INTERFACE); 2962 2963 return genlmsg_reply(msg, info); 2964 } 2965 2966 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info) 2967 { 2968 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2969 struct wireless_dev *wdev = info->user_ptr[1]; 2970 2971 if (!rdev->ops->del_virtual_intf) 2972 return -EOPNOTSUPP; 2973 2974 /* 2975 * If we remove a wireless device without a netdev then clear 2976 * user_ptr[1] so that nl80211_post_doit won't dereference it 2977 * to check if it needs to do dev_put(). Otherwise it crashes 2978 * since the wdev has been freed, unlike with a netdev where 2979 * we need the dev_put() for the netdev to really be freed. 2980 */ 2981 if (!wdev->netdev) 2982 info->user_ptr[1] = NULL; 2983 2984 return rdev_del_virtual_intf(rdev, wdev); 2985 } 2986 2987 static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info) 2988 { 2989 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2990 struct net_device *dev = info->user_ptr[1]; 2991 u16 noack_map; 2992 2993 if (!info->attrs[NL80211_ATTR_NOACK_MAP]) 2994 return -EINVAL; 2995 2996 if (!rdev->ops->set_noack_map) 2997 return -EOPNOTSUPP; 2998 2999 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]); 3000 3001 return rdev_set_noack_map(rdev, dev, noack_map); 3002 } 3003 3004 struct get_key_cookie { 3005 struct sk_buff *msg; 3006 int error; 3007 int idx; 3008 }; 3009 3010 static void get_key_callback(void *c, struct key_params *params) 3011 { 3012 struct nlattr *key; 3013 struct get_key_cookie *cookie = c; 3014 3015 if ((params->key && 3016 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA, 3017 params->key_len, params->key)) || 3018 (params->seq && 3019 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ, 3020 params->seq_len, params->seq)) || 3021 (params->cipher && 3022 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER, 3023 params->cipher))) 3024 goto nla_put_failure; 3025 3026 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY); 3027 if (!key) 3028 goto nla_put_failure; 3029 3030 if ((params->key && 3031 nla_put(cookie->msg, NL80211_KEY_DATA, 3032 params->key_len, params->key)) || 3033 (params->seq && 3034 nla_put(cookie->msg, NL80211_KEY_SEQ, 3035 params->seq_len, params->seq)) || 3036 (params->cipher && 3037 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER, 3038 params->cipher))) 3039 goto nla_put_failure; 3040 3041 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx)) 3042 goto nla_put_failure; 3043 3044 nla_nest_end(cookie->msg, key); 3045 3046 return; 3047 nla_put_failure: 3048 cookie->error = 1; 3049 } 3050 3051 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info) 3052 { 3053 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3054 int err; 3055 struct net_device *dev = info->user_ptr[1]; 3056 u8 key_idx = 0; 3057 const u8 *mac_addr = NULL; 3058 bool pairwise; 3059 struct get_key_cookie cookie = { 3060 .error = 0, 3061 }; 3062 void *hdr; 3063 struct sk_buff *msg; 3064 3065 if (info->attrs[NL80211_ATTR_KEY_IDX]) 3066 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]); 3067 3068 if (key_idx > 5) 3069 return -EINVAL; 3070 3071 if (info->attrs[NL80211_ATTR_MAC]) 3072 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 3073 3074 pairwise = !!mac_addr; 3075 if (info->attrs[NL80211_ATTR_KEY_TYPE]) { 3076 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]); 3077 3078 if (kt >= NUM_NL80211_KEYTYPES) 3079 return -EINVAL; 3080 if (kt != NL80211_KEYTYPE_GROUP && 3081 kt != NL80211_KEYTYPE_PAIRWISE) 3082 return -EINVAL; 3083 pairwise = kt == NL80211_KEYTYPE_PAIRWISE; 3084 } 3085 3086 if (!rdev->ops->get_key) 3087 return -EOPNOTSUPP; 3088 3089 if (!pairwise && mac_addr && !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)) 3090 return -ENOENT; 3091 3092 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 3093 if (!msg) 3094 return -ENOMEM; 3095 3096 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 3097 NL80211_CMD_NEW_KEY); 3098 if (!hdr) 3099 goto nla_put_failure; 3100 3101 cookie.msg = msg; 3102 cookie.idx = key_idx; 3103 3104 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 3105 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx)) 3106 goto nla_put_failure; 3107 if (mac_addr && 3108 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr)) 3109 goto nla_put_failure; 3110 3111 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie, 3112 get_key_callback); 3113 3114 if (err) 3115 goto free_msg; 3116 3117 if (cookie.error) 3118 goto nla_put_failure; 3119 3120 genlmsg_end(msg, hdr); 3121 return genlmsg_reply(msg, info); 3122 3123 nla_put_failure: 3124 err = -ENOBUFS; 3125 free_msg: 3126 nlmsg_free(msg); 3127 return err; 3128 } 3129 3130 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info) 3131 { 3132 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3133 struct key_parse key; 3134 int err; 3135 struct net_device *dev = info->user_ptr[1]; 3136 3137 err = nl80211_parse_key(info, &key); 3138 if (err) 3139 return err; 3140 3141 if (key.idx < 0) 3142 return -EINVAL; 3143 3144 /* only support setting default key */ 3145 if (!key.def && !key.defmgmt) 3146 return -EINVAL; 3147 3148 wdev_lock(dev->ieee80211_ptr); 3149 3150 if (key.def) { 3151 if (!rdev->ops->set_default_key) { 3152 err = -EOPNOTSUPP; 3153 goto out; 3154 } 3155 3156 err = nl80211_key_allowed(dev->ieee80211_ptr); 3157 if (err) 3158 goto out; 3159 3160 err = rdev_set_default_key(rdev, dev, key.idx, 3161 key.def_uni, key.def_multi); 3162 3163 if (err) 3164 goto out; 3165 3166 #ifdef CONFIG_CFG80211_WEXT 3167 dev->ieee80211_ptr->wext.default_key = key.idx; 3168 #endif 3169 } else { 3170 if (key.def_uni || !key.def_multi) { 3171 err = -EINVAL; 3172 goto out; 3173 } 3174 3175 if (!rdev->ops->set_default_mgmt_key) { 3176 err = -EOPNOTSUPP; 3177 goto out; 3178 } 3179 3180 err = nl80211_key_allowed(dev->ieee80211_ptr); 3181 if (err) 3182 goto out; 3183 3184 err = rdev_set_default_mgmt_key(rdev, dev, key.idx); 3185 if (err) 3186 goto out; 3187 3188 #ifdef CONFIG_CFG80211_WEXT 3189 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx; 3190 #endif 3191 } 3192 3193 out: 3194 wdev_unlock(dev->ieee80211_ptr); 3195 3196 return err; 3197 } 3198 3199 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info) 3200 { 3201 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3202 int err; 3203 struct net_device *dev = info->user_ptr[1]; 3204 struct key_parse key; 3205 const u8 *mac_addr = NULL; 3206 3207 err = nl80211_parse_key(info, &key); 3208 if (err) 3209 return err; 3210 3211 if (!key.p.key) 3212 return -EINVAL; 3213 3214 if (info->attrs[NL80211_ATTR_MAC]) 3215 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 3216 3217 if (key.type == -1) { 3218 if (mac_addr) 3219 key.type = NL80211_KEYTYPE_PAIRWISE; 3220 else 3221 key.type = NL80211_KEYTYPE_GROUP; 3222 } 3223 3224 /* for now */ 3225 if (key.type != NL80211_KEYTYPE_PAIRWISE && 3226 key.type != NL80211_KEYTYPE_GROUP) 3227 return -EINVAL; 3228 3229 if (!rdev->ops->add_key) 3230 return -EOPNOTSUPP; 3231 3232 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, 3233 key.type == NL80211_KEYTYPE_PAIRWISE, 3234 mac_addr)) 3235 return -EINVAL; 3236 3237 wdev_lock(dev->ieee80211_ptr); 3238 err = nl80211_key_allowed(dev->ieee80211_ptr); 3239 if (!err) 3240 err = rdev_add_key(rdev, dev, key.idx, 3241 key.type == NL80211_KEYTYPE_PAIRWISE, 3242 mac_addr, &key.p); 3243 wdev_unlock(dev->ieee80211_ptr); 3244 3245 return err; 3246 } 3247 3248 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info) 3249 { 3250 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3251 int err; 3252 struct net_device *dev = info->user_ptr[1]; 3253 u8 *mac_addr = NULL; 3254 struct key_parse key; 3255 3256 err = nl80211_parse_key(info, &key); 3257 if (err) 3258 return err; 3259 3260 if (info->attrs[NL80211_ATTR_MAC]) 3261 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 3262 3263 if (key.type == -1) { 3264 if (mac_addr) 3265 key.type = NL80211_KEYTYPE_PAIRWISE; 3266 else 3267 key.type = NL80211_KEYTYPE_GROUP; 3268 } 3269 3270 /* for now */ 3271 if (key.type != NL80211_KEYTYPE_PAIRWISE && 3272 key.type != NL80211_KEYTYPE_GROUP) 3273 return -EINVAL; 3274 3275 if (!rdev->ops->del_key) 3276 return -EOPNOTSUPP; 3277 3278 wdev_lock(dev->ieee80211_ptr); 3279 err = nl80211_key_allowed(dev->ieee80211_ptr); 3280 3281 if (key.type == NL80211_KEYTYPE_GROUP && mac_addr && 3282 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)) 3283 err = -ENOENT; 3284 3285 if (!err) 3286 err = rdev_del_key(rdev, dev, key.idx, 3287 key.type == NL80211_KEYTYPE_PAIRWISE, 3288 mac_addr); 3289 3290 #ifdef CONFIG_CFG80211_WEXT 3291 if (!err) { 3292 if (key.idx == dev->ieee80211_ptr->wext.default_key) 3293 dev->ieee80211_ptr->wext.default_key = -1; 3294 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key) 3295 dev->ieee80211_ptr->wext.default_mgmt_key = -1; 3296 } 3297 #endif 3298 wdev_unlock(dev->ieee80211_ptr); 3299 3300 return err; 3301 } 3302 3303 /* This function returns an error or the number of nested attributes */ 3304 static int validate_acl_mac_addrs(struct nlattr *nl_attr) 3305 { 3306 struct nlattr *attr; 3307 int n_entries = 0, tmp; 3308 3309 nla_for_each_nested(attr, nl_attr, tmp) { 3310 if (nla_len(attr) != ETH_ALEN) 3311 return -EINVAL; 3312 3313 n_entries++; 3314 } 3315 3316 return n_entries; 3317 } 3318 3319 /* 3320 * This function parses ACL information and allocates memory for ACL data. 3321 * On successful return, the calling function is responsible to free the 3322 * ACL buffer returned by this function. 3323 */ 3324 static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy, 3325 struct genl_info *info) 3326 { 3327 enum nl80211_acl_policy acl_policy; 3328 struct nlattr *attr; 3329 struct cfg80211_acl_data *acl; 3330 int i = 0, n_entries, tmp; 3331 3332 if (!wiphy->max_acl_mac_addrs) 3333 return ERR_PTR(-EOPNOTSUPP); 3334 3335 if (!info->attrs[NL80211_ATTR_ACL_POLICY]) 3336 return ERR_PTR(-EINVAL); 3337 3338 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]); 3339 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED && 3340 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED) 3341 return ERR_PTR(-EINVAL); 3342 3343 if (!info->attrs[NL80211_ATTR_MAC_ADDRS]) 3344 return ERR_PTR(-EINVAL); 3345 3346 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]); 3347 if (n_entries < 0) 3348 return ERR_PTR(n_entries); 3349 3350 if (n_entries > wiphy->max_acl_mac_addrs) 3351 return ERR_PTR(-ENOTSUPP); 3352 3353 acl = kzalloc(sizeof(*acl) + (sizeof(struct mac_address) * n_entries), 3354 GFP_KERNEL); 3355 if (!acl) 3356 return ERR_PTR(-ENOMEM); 3357 3358 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) { 3359 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN); 3360 i++; 3361 } 3362 3363 acl->n_acl_entries = n_entries; 3364 acl->acl_policy = acl_policy; 3365 3366 return acl; 3367 } 3368 3369 static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info) 3370 { 3371 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3372 struct net_device *dev = info->user_ptr[1]; 3373 struct cfg80211_acl_data *acl; 3374 int err; 3375 3376 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 3377 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3378 return -EOPNOTSUPP; 3379 3380 if (!dev->ieee80211_ptr->beacon_interval) 3381 return -EINVAL; 3382 3383 acl = parse_acl_data(&rdev->wiphy, info); 3384 if (IS_ERR(acl)) 3385 return PTR_ERR(acl); 3386 3387 err = rdev_set_mac_acl(rdev, dev, acl); 3388 3389 kfree(acl); 3390 3391 return err; 3392 } 3393 3394 static u32 rateset_to_mask(struct ieee80211_supported_band *sband, 3395 u8 *rates, u8 rates_len) 3396 { 3397 u8 i; 3398 u32 mask = 0; 3399 3400 for (i = 0; i < rates_len; i++) { 3401 int rate = (rates[i] & 0x7f) * 5; 3402 int ridx; 3403 3404 for (ridx = 0; ridx < sband->n_bitrates; ridx++) { 3405 struct ieee80211_rate *srate = 3406 &sband->bitrates[ridx]; 3407 if (rate == srate->bitrate) { 3408 mask |= 1 << ridx; 3409 break; 3410 } 3411 } 3412 if (ridx == sband->n_bitrates) 3413 return 0; /* rate not found */ 3414 } 3415 3416 return mask; 3417 } 3418 3419 static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband, 3420 u8 *rates, u8 rates_len, 3421 u8 mcs[IEEE80211_HT_MCS_MASK_LEN]) 3422 { 3423 u8 i; 3424 3425 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN); 3426 3427 for (i = 0; i < rates_len; i++) { 3428 int ridx, rbit; 3429 3430 ridx = rates[i] / 8; 3431 rbit = BIT(rates[i] % 8); 3432 3433 /* check validity */ 3434 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN)) 3435 return false; 3436 3437 /* check availability */ 3438 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit) 3439 mcs[ridx] |= rbit; 3440 else 3441 return false; 3442 } 3443 3444 return true; 3445 } 3446 3447 static u16 vht_mcs_map_to_mcs_mask(u8 vht_mcs_map) 3448 { 3449 u16 mcs_mask = 0; 3450 3451 switch (vht_mcs_map) { 3452 case IEEE80211_VHT_MCS_NOT_SUPPORTED: 3453 break; 3454 case IEEE80211_VHT_MCS_SUPPORT_0_7: 3455 mcs_mask = 0x00FF; 3456 break; 3457 case IEEE80211_VHT_MCS_SUPPORT_0_8: 3458 mcs_mask = 0x01FF; 3459 break; 3460 case IEEE80211_VHT_MCS_SUPPORT_0_9: 3461 mcs_mask = 0x03FF; 3462 break; 3463 default: 3464 break; 3465 } 3466 3467 return mcs_mask; 3468 } 3469 3470 static void vht_build_mcs_mask(u16 vht_mcs_map, 3471 u16 vht_mcs_mask[NL80211_VHT_NSS_MAX]) 3472 { 3473 u8 nss; 3474 3475 for (nss = 0; nss < NL80211_VHT_NSS_MAX; nss++) { 3476 vht_mcs_mask[nss] = vht_mcs_map_to_mcs_mask(vht_mcs_map & 0x03); 3477 vht_mcs_map >>= 2; 3478 } 3479 } 3480 3481 static bool vht_set_mcs_mask(struct ieee80211_supported_band *sband, 3482 struct nl80211_txrate_vht *txrate, 3483 u16 mcs[NL80211_VHT_NSS_MAX]) 3484 { 3485 u16 tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map); 3486 u16 tx_mcs_mask[NL80211_VHT_NSS_MAX] = {}; 3487 u8 i; 3488 3489 if (!sband->vht_cap.vht_supported) 3490 return false; 3491 3492 memset(mcs, 0, sizeof(u16) * NL80211_VHT_NSS_MAX); 3493 3494 /* Build vht_mcs_mask from VHT capabilities */ 3495 vht_build_mcs_mask(tx_mcs_map, tx_mcs_mask); 3496 3497 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) { 3498 if ((tx_mcs_mask[i] & txrate->mcs[i]) == txrate->mcs[i]) 3499 mcs[i] = txrate->mcs[i]; 3500 else 3501 return false; 3502 } 3503 3504 return true; 3505 } 3506 3507 static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = { 3508 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY, 3509 .len = NL80211_MAX_SUPP_RATES }, 3510 [NL80211_TXRATE_HT] = { .type = NLA_BINARY, 3511 .len = NL80211_MAX_SUPP_HT_RATES }, 3512 [NL80211_TXRATE_VHT] = { .len = sizeof(struct nl80211_txrate_vht)}, 3513 [NL80211_TXRATE_GI] = { .type = NLA_U8 }, 3514 }; 3515 3516 static int nl80211_parse_tx_bitrate_mask(struct genl_info *info, 3517 struct cfg80211_bitrate_mask *mask) 3518 { 3519 struct nlattr *tb[NL80211_TXRATE_MAX + 1]; 3520 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3521 int rem, i; 3522 struct nlattr *tx_rates; 3523 struct ieee80211_supported_band *sband; 3524 u16 vht_tx_mcs_map; 3525 3526 memset(mask, 0, sizeof(*mask)); 3527 /* Default to all rates enabled */ 3528 for (i = 0; i < NUM_NL80211_BANDS; i++) { 3529 sband = rdev->wiphy.bands[i]; 3530 3531 if (!sband) 3532 continue; 3533 3534 mask->control[i].legacy = (1 << sband->n_bitrates) - 1; 3535 memcpy(mask->control[i].ht_mcs, 3536 sband->ht_cap.mcs.rx_mask, 3537 sizeof(mask->control[i].ht_mcs)); 3538 3539 if (!sband->vht_cap.vht_supported) 3540 continue; 3541 3542 vht_tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map); 3543 vht_build_mcs_mask(vht_tx_mcs_map, mask->control[i].vht_mcs); 3544 } 3545 3546 /* if no rates are given set it back to the defaults */ 3547 if (!info->attrs[NL80211_ATTR_TX_RATES]) 3548 goto out; 3549 3550 /* The nested attribute uses enum nl80211_band as the index. This maps 3551 * directly to the enum nl80211_band values used in cfg80211. 3552 */ 3553 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8); 3554 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem) { 3555 enum nl80211_band band = nla_type(tx_rates); 3556 int err; 3557 3558 if (band < 0 || band >= NUM_NL80211_BANDS) 3559 return -EINVAL; 3560 sband = rdev->wiphy.bands[band]; 3561 if (sband == NULL) 3562 return -EINVAL; 3563 err = nla_parse_nested(tb, NL80211_TXRATE_MAX, tx_rates, 3564 nl80211_txattr_policy); 3565 if (err) 3566 return err; 3567 if (tb[NL80211_TXRATE_LEGACY]) { 3568 mask->control[band].legacy = rateset_to_mask( 3569 sband, 3570 nla_data(tb[NL80211_TXRATE_LEGACY]), 3571 nla_len(tb[NL80211_TXRATE_LEGACY])); 3572 if ((mask->control[band].legacy == 0) && 3573 nla_len(tb[NL80211_TXRATE_LEGACY])) 3574 return -EINVAL; 3575 } 3576 if (tb[NL80211_TXRATE_HT]) { 3577 if (!ht_rateset_to_mask( 3578 sband, 3579 nla_data(tb[NL80211_TXRATE_HT]), 3580 nla_len(tb[NL80211_TXRATE_HT]), 3581 mask->control[band].ht_mcs)) 3582 return -EINVAL; 3583 } 3584 if (tb[NL80211_TXRATE_VHT]) { 3585 if (!vht_set_mcs_mask( 3586 sband, 3587 nla_data(tb[NL80211_TXRATE_VHT]), 3588 mask->control[band].vht_mcs)) 3589 return -EINVAL; 3590 } 3591 if (tb[NL80211_TXRATE_GI]) { 3592 mask->control[band].gi = 3593 nla_get_u8(tb[NL80211_TXRATE_GI]); 3594 if (mask->control[band].gi > NL80211_TXRATE_FORCE_LGI) 3595 return -EINVAL; 3596 } 3597 3598 if (mask->control[band].legacy == 0) { 3599 /* don't allow empty legacy rates if HT or VHT 3600 * are not even supported. 3601 */ 3602 if (!(rdev->wiphy.bands[band]->ht_cap.ht_supported || 3603 rdev->wiphy.bands[band]->vht_cap.vht_supported)) 3604 return -EINVAL; 3605 3606 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++) 3607 if (mask->control[band].ht_mcs[i]) 3608 goto out; 3609 3610 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) 3611 if (mask->control[band].vht_mcs[i]) 3612 goto out; 3613 3614 /* legacy and mcs rates may not be both empty */ 3615 return -EINVAL; 3616 } 3617 } 3618 3619 out: 3620 return 0; 3621 } 3622 3623 static int validate_beacon_tx_rate(struct cfg80211_registered_device *rdev, 3624 enum nl80211_band band, 3625 struct cfg80211_bitrate_mask *beacon_rate) 3626 { 3627 u32 count_ht, count_vht, i; 3628 u32 rate = beacon_rate->control[band].legacy; 3629 3630 /* Allow only one rate */ 3631 if (hweight32(rate) > 1) 3632 return -EINVAL; 3633 3634 count_ht = 0; 3635 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++) { 3636 if (hweight8(beacon_rate->control[band].ht_mcs[i]) > 1) { 3637 return -EINVAL; 3638 } else if (beacon_rate->control[band].ht_mcs[i]) { 3639 count_ht++; 3640 if (count_ht > 1) 3641 return -EINVAL; 3642 } 3643 if (count_ht && rate) 3644 return -EINVAL; 3645 } 3646 3647 count_vht = 0; 3648 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) { 3649 if (hweight16(beacon_rate->control[band].vht_mcs[i]) > 1) { 3650 return -EINVAL; 3651 } else if (beacon_rate->control[band].vht_mcs[i]) { 3652 count_vht++; 3653 if (count_vht > 1) 3654 return -EINVAL; 3655 } 3656 if (count_vht && rate) 3657 return -EINVAL; 3658 } 3659 3660 if ((count_ht && count_vht) || (!rate && !count_ht && !count_vht)) 3661 return -EINVAL; 3662 3663 if (rate && 3664 !wiphy_ext_feature_isset(&rdev->wiphy, 3665 NL80211_EXT_FEATURE_BEACON_RATE_LEGACY)) 3666 return -EINVAL; 3667 if (count_ht && 3668 !wiphy_ext_feature_isset(&rdev->wiphy, 3669 NL80211_EXT_FEATURE_BEACON_RATE_HT)) 3670 return -EINVAL; 3671 if (count_vht && 3672 !wiphy_ext_feature_isset(&rdev->wiphy, 3673 NL80211_EXT_FEATURE_BEACON_RATE_VHT)) 3674 return -EINVAL; 3675 3676 return 0; 3677 } 3678 3679 static int nl80211_parse_beacon(struct nlattr *attrs[], 3680 struct cfg80211_beacon_data *bcn) 3681 { 3682 bool haveinfo = false; 3683 3684 if (!is_valid_ie_attr(attrs[NL80211_ATTR_BEACON_TAIL]) || 3685 !is_valid_ie_attr(attrs[NL80211_ATTR_IE]) || 3686 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_PROBE_RESP]) || 3687 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_ASSOC_RESP])) 3688 return -EINVAL; 3689 3690 memset(bcn, 0, sizeof(*bcn)); 3691 3692 if (attrs[NL80211_ATTR_BEACON_HEAD]) { 3693 bcn->head = nla_data(attrs[NL80211_ATTR_BEACON_HEAD]); 3694 bcn->head_len = nla_len(attrs[NL80211_ATTR_BEACON_HEAD]); 3695 if (!bcn->head_len) 3696 return -EINVAL; 3697 haveinfo = true; 3698 } 3699 3700 if (attrs[NL80211_ATTR_BEACON_TAIL]) { 3701 bcn->tail = nla_data(attrs[NL80211_ATTR_BEACON_TAIL]); 3702 bcn->tail_len = nla_len(attrs[NL80211_ATTR_BEACON_TAIL]); 3703 haveinfo = true; 3704 } 3705 3706 if (!haveinfo) 3707 return -EINVAL; 3708 3709 if (attrs[NL80211_ATTR_IE]) { 3710 bcn->beacon_ies = nla_data(attrs[NL80211_ATTR_IE]); 3711 bcn->beacon_ies_len = nla_len(attrs[NL80211_ATTR_IE]); 3712 } 3713 3714 if (attrs[NL80211_ATTR_IE_PROBE_RESP]) { 3715 bcn->proberesp_ies = 3716 nla_data(attrs[NL80211_ATTR_IE_PROBE_RESP]); 3717 bcn->proberesp_ies_len = 3718 nla_len(attrs[NL80211_ATTR_IE_PROBE_RESP]); 3719 } 3720 3721 if (attrs[NL80211_ATTR_IE_ASSOC_RESP]) { 3722 bcn->assocresp_ies = 3723 nla_data(attrs[NL80211_ATTR_IE_ASSOC_RESP]); 3724 bcn->assocresp_ies_len = 3725 nla_len(attrs[NL80211_ATTR_IE_ASSOC_RESP]); 3726 } 3727 3728 if (attrs[NL80211_ATTR_PROBE_RESP]) { 3729 bcn->probe_resp = nla_data(attrs[NL80211_ATTR_PROBE_RESP]); 3730 bcn->probe_resp_len = nla_len(attrs[NL80211_ATTR_PROBE_RESP]); 3731 } 3732 3733 return 0; 3734 } 3735 3736 static void nl80211_check_ap_rate_selectors(struct cfg80211_ap_settings *params, 3737 const u8 *rates) 3738 { 3739 int i; 3740 3741 if (!rates) 3742 return; 3743 3744 for (i = 0; i < rates[1]; i++) { 3745 if (rates[2 + i] == BSS_MEMBERSHIP_SELECTOR_HT_PHY) 3746 params->ht_required = true; 3747 if (rates[2 + i] == BSS_MEMBERSHIP_SELECTOR_VHT_PHY) 3748 params->vht_required = true; 3749 } 3750 } 3751 3752 /* 3753 * Since the nl80211 API didn't include, from the beginning, attributes about 3754 * HT/VHT requirements/capabilities, we parse them out of the IEs for the 3755 * benefit of drivers that rebuild IEs in the firmware. 3756 */ 3757 static void nl80211_calculate_ap_params(struct cfg80211_ap_settings *params) 3758 { 3759 const struct cfg80211_beacon_data *bcn = ¶ms->beacon; 3760 size_t ies_len = bcn->beacon_ies_len; 3761 const u8 *ies = bcn->beacon_ies; 3762 const u8 *rates; 3763 const u8 *cap; 3764 3765 rates = cfg80211_find_ie(WLAN_EID_SUPP_RATES, ies, ies_len); 3766 nl80211_check_ap_rate_selectors(params, rates); 3767 3768 rates = cfg80211_find_ie(WLAN_EID_EXT_SUPP_RATES, ies, ies_len); 3769 nl80211_check_ap_rate_selectors(params, rates); 3770 3771 cap = cfg80211_find_ie(WLAN_EID_HT_CAPABILITY, ies, ies_len); 3772 if (cap && cap[1] >= sizeof(*params->ht_cap)) 3773 params->ht_cap = (void *)(cap + 2); 3774 cap = cfg80211_find_ie(WLAN_EID_VHT_CAPABILITY, ies, ies_len); 3775 if (cap && cap[1] >= sizeof(*params->vht_cap)) 3776 params->vht_cap = (void *)(cap + 2); 3777 } 3778 3779 static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev, 3780 struct cfg80211_ap_settings *params) 3781 { 3782 struct wireless_dev *wdev; 3783 bool ret = false; 3784 3785 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) { 3786 if (wdev->iftype != NL80211_IFTYPE_AP && 3787 wdev->iftype != NL80211_IFTYPE_P2P_GO) 3788 continue; 3789 3790 if (!wdev->preset_chandef.chan) 3791 continue; 3792 3793 params->chandef = wdev->preset_chandef; 3794 ret = true; 3795 break; 3796 } 3797 3798 return ret; 3799 } 3800 3801 static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev, 3802 enum nl80211_auth_type auth_type, 3803 enum nl80211_commands cmd) 3804 { 3805 if (auth_type > NL80211_AUTHTYPE_MAX) 3806 return false; 3807 3808 switch (cmd) { 3809 case NL80211_CMD_AUTHENTICATE: 3810 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) && 3811 auth_type == NL80211_AUTHTYPE_SAE) 3812 return false; 3813 if (!wiphy_ext_feature_isset(&rdev->wiphy, 3814 NL80211_EXT_FEATURE_FILS_STA) && 3815 (auth_type == NL80211_AUTHTYPE_FILS_SK || 3816 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS || 3817 auth_type == NL80211_AUTHTYPE_FILS_PK)) 3818 return false; 3819 return true; 3820 case NL80211_CMD_CONNECT: 3821 case NL80211_CMD_START_AP: 3822 /* SAE not supported yet */ 3823 if (auth_type == NL80211_AUTHTYPE_SAE) 3824 return false; 3825 /* FILS not supported yet */ 3826 if (auth_type == NL80211_AUTHTYPE_FILS_SK || 3827 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS || 3828 auth_type == NL80211_AUTHTYPE_FILS_PK) 3829 return false; 3830 return true; 3831 default: 3832 return false; 3833 } 3834 } 3835 3836 static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info) 3837 { 3838 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3839 struct net_device *dev = info->user_ptr[1]; 3840 struct wireless_dev *wdev = dev->ieee80211_ptr; 3841 struct cfg80211_ap_settings params; 3842 int err; 3843 3844 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 3845 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3846 return -EOPNOTSUPP; 3847 3848 if (!rdev->ops->start_ap) 3849 return -EOPNOTSUPP; 3850 3851 if (wdev->beacon_interval) 3852 return -EALREADY; 3853 3854 memset(¶ms, 0, sizeof(params)); 3855 3856 /* these are required for START_AP */ 3857 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] || 3858 !info->attrs[NL80211_ATTR_DTIM_PERIOD] || 3859 !info->attrs[NL80211_ATTR_BEACON_HEAD]) 3860 return -EINVAL; 3861 3862 err = nl80211_parse_beacon(info->attrs, ¶ms.beacon); 3863 if (err) 3864 return err; 3865 3866 params.beacon_interval = 3867 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]); 3868 params.dtim_period = 3869 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]); 3870 3871 err = cfg80211_validate_beacon_int(rdev, dev->ieee80211_ptr->iftype, 3872 params.beacon_interval); 3873 if (err) 3874 return err; 3875 3876 /* 3877 * In theory, some of these attributes should be required here 3878 * but since they were not used when the command was originally 3879 * added, keep them optional for old user space programs to let 3880 * them continue to work with drivers that do not need the 3881 * additional information -- drivers must check! 3882 */ 3883 if (info->attrs[NL80211_ATTR_SSID]) { 3884 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 3885 params.ssid_len = 3886 nla_len(info->attrs[NL80211_ATTR_SSID]); 3887 if (params.ssid_len == 0 || 3888 params.ssid_len > IEEE80211_MAX_SSID_LEN) 3889 return -EINVAL; 3890 } 3891 3892 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) { 3893 params.hidden_ssid = nla_get_u32( 3894 info->attrs[NL80211_ATTR_HIDDEN_SSID]); 3895 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE && 3896 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN && 3897 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS) 3898 return -EINVAL; 3899 } 3900 3901 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY]; 3902 3903 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) { 3904 params.auth_type = nla_get_u32( 3905 info->attrs[NL80211_ATTR_AUTH_TYPE]); 3906 if (!nl80211_valid_auth_type(rdev, params.auth_type, 3907 NL80211_CMD_START_AP)) 3908 return -EINVAL; 3909 } else 3910 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC; 3911 3912 err = nl80211_crypto_settings(rdev, info, ¶ms.crypto, 3913 NL80211_MAX_NR_CIPHER_SUITES); 3914 if (err) 3915 return err; 3916 3917 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) { 3918 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER)) 3919 return -EOPNOTSUPP; 3920 params.inactivity_timeout = nla_get_u16( 3921 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]); 3922 } 3923 3924 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) { 3925 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3926 return -EINVAL; 3927 params.p2p_ctwindow = 3928 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]); 3929 if (params.p2p_ctwindow > 127) 3930 return -EINVAL; 3931 if (params.p2p_ctwindow != 0 && 3932 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN)) 3933 return -EINVAL; 3934 } 3935 3936 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) { 3937 u8 tmp; 3938 3939 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3940 return -EINVAL; 3941 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]); 3942 if (tmp > 1) 3943 return -EINVAL; 3944 params.p2p_opp_ps = tmp; 3945 if (params.p2p_opp_ps != 0 && 3946 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS)) 3947 return -EINVAL; 3948 } 3949 3950 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 3951 err = nl80211_parse_chandef(rdev, info, ¶ms.chandef); 3952 if (err) 3953 return err; 3954 } else if (wdev->preset_chandef.chan) { 3955 params.chandef = wdev->preset_chandef; 3956 } else if (!nl80211_get_ap_channel(rdev, ¶ms)) 3957 return -EINVAL; 3958 3959 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, ¶ms.chandef, 3960 wdev->iftype)) 3961 return -EINVAL; 3962 3963 if (info->attrs[NL80211_ATTR_TX_RATES]) { 3964 err = nl80211_parse_tx_bitrate_mask(info, ¶ms.beacon_rate); 3965 if (err) 3966 return err; 3967 3968 err = validate_beacon_tx_rate(rdev, params.chandef.chan->band, 3969 ¶ms.beacon_rate); 3970 if (err) 3971 return err; 3972 } 3973 3974 if (info->attrs[NL80211_ATTR_SMPS_MODE]) { 3975 params.smps_mode = 3976 nla_get_u8(info->attrs[NL80211_ATTR_SMPS_MODE]); 3977 switch (params.smps_mode) { 3978 case NL80211_SMPS_OFF: 3979 break; 3980 case NL80211_SMPS_STATIC: 3981 if (!(rdev->wiphy.features & 3982 NL80211_FEATURE_STATIC_SMPS)) 3983 return -EINVAL; 3984 break; 3985 case NL80211_SMPS_DYNAMIC: 3986 if (!(rdev->wiphy.features & 3987 NL80211_FEATURE_DYNAMIC_SMPS)) 3988 return -EINVAL; 3989 break; 3990 default: 3991 return -EINVAL; 3992 } 3993 } else { 3994 params.smps_mode = NL80211_SMPS_OFF; 3995 } 3996 3997 params.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]); 3998 if (params.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ]) 3999 return -EOPNOTSUPP; 4000 4001 if (info->attrs[NL80211_ATTR_ACL_POLICY]) { 4002 params.acl = parse_acl_data(&rdev->wiphy, info); 4003 if (IS_ERR(params.acl)) 4004 return PTR_ERR(params.acl); 4005 } 4006 4007 nl80211_calculate_ap_params(¶ms); 4008 4009 wdev_lock(wdev); 4010 err = rdev_start_ap(rdev, dev, ¶ms); 4011 if (!err) { 4012 wdev->preset_chandef = params.chandef; 4013 wdev->beacon_interval = params.beacon_interval; 4014 wdev->chandef = params.chandef; 4015 wdev->ssid_len = params.ssid_len; 4016 memcpy(wdev->ssid, params.ssid, wdev->ssid_len); 4017 } 4018 wdev_unlock(wdev); 4019 4020 kfree(params.acl); 4021 4022 return err; 4023 } 4024 4025 static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info) 4026 { 4027 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 4028 struct net_device *dev = info->user_ptr[1]; 4029 struct wireless_dev *wdev = dev->ieee80211_ptr; 4030 struct cfg80211_beacon_data params; 4031 int err; 4032 4033 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 4034 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 4035 return -EOPNOTSUPP; 4036 4037 if (!rdev->ops->change_beacon) 4038 return -EOPNOTSUPP; 4039 4040 if (!wdev->beacon_interval) 4041 return -EINVAL; 4042 4043 err = nl80211_parse_beacon(info->attrs, ¶ms); 4044 if (err) 4045 return err; 4046 4047 wdev_lock(wdev); 4048 err = rdev_change_beacon(rdev, dev, ¶ms); 4049 wdev_unlock(wdev); 4050 4051 return err; 4052 } 4053 4054 static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info) 4055 { 4056 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 4057 struct net_device *dev = info->user_ptr[1]; 4058 4059 return cfg80211_stop_ap(rdev, dev, false); 4060 } 4061 4062 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = { 4063 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG }, 4064 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG }, 4065 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG }, 4066 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG }, 4067 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG }, 4068 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG }, 4069 }; 4070 4071 static int parse_station_flags(struct genl_info *info, 4072 enum nl80211_iftype iftype, 4073 struct station_parameters *params) 4074 { 4075 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1]; 4076 struct nlattr *nla; 4077 int flag; 4078 4079 /* 4080 * Try parsing the new attribute first so userspace 4081 * can specify both for older kernels. 4082 */ 4083 nla = info->attrs[NL80211_ATTR_STA_FLAGS2]; 4084 if (nla) { 4085 struct nl80211_sta_flag_update *sta_flags; 4086 4087 sta_flags = nla_data(nla); 4088 params->sta_flags_mask = sta_flags->mask; 4089 params->sta_flags_set = sta_flags->set; 4090 params->sta_flags_set &= params->sta_flags_mask; 4091 if ((params->sta_flags_mask | 4092 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID)) 4093 return -EINVAL; 4094 return 0; 4095 } 4096 4097 /* if present, parse the old attribute */ 4098 4099 nla = info->attrs[NL80211_ATTR_STA_FLAGS]; 4100 if (!nla) 4101 return 0; 4102 4103 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX, 4104 nla, sta_flags_policy)) 4105 return -EINVAL; 4106 4107 /* 4108 * Only allow certain flags for interface types so that 4109 * other attributes are silently ignored. Remember that 4110 * this is backward compatibility code with old userspace 4111 * and shouldn't be hit in other cases anyway. 4112 */ 4113 switch (iftype) { 4114 case NL80211_IFTYPE_AP: 4115 case NL80211_IFTYPE_AP_VLAN: 4116 case NL80211_IFTYPE_P2P_GO: 4117 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) | 4118 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) | 4119 BIT(NL80211_STA_FLAG_WME) | 4120 BIT(NL80211_STA_FLAG_MFP); 4121 break; 4122 case NL80211_IFTYPE_P2P_CLIENT: 4123 case NL80211_IFTYPE_STATION: 4124 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) | 4125 BIT(NL80211_STA_FLAG_TDLS_PEER); 4126 break; 4127 case NL80211_IFTYPE_MESH_POINT: 4128 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4129 BIT(NL80211_STA_FLAG_MFP) | 4130 BIT(NL80211_STA_FLAG_AUTHORIZED); 4131 default: 4132 return -EINVAL; 4133 } 4134 4135 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) { 4136 if (flags[flag]) { 4137 params->sta_flags_set |= (1<<flag); 4138 4139 /* no longer support new API additions in old API */ 4140 if (flag > NL80211_STA_FLAG_MAX_OLD_API) 4141 return -EINVAL; 4142 } 4143 } 4144 4145 return 0; 4146 } 4147 4148 static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info, 4149 int attr) 4150 { 4151 struct nlattr *rate; 4152 u32 bitrate; 4153 u16 bitrate_compat; 4154 enum nl80211_attrs rate_flg; 4155 4156 rate = nla_nest_start(msg, attr); 4157 if (!rate) 4158 return false; 4159 4160 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */ 4161 bitrate = cfg80211_calculate_bitrate(info); 4162 /* report 16-bit bitrate only if we can */ 4163 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0; 4164 if (bitrate > 0 && 4165 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate)) 4166 return false; 4167 if (bitrate_compat > 0 && 4168 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat)) 4169 return false; 4170 4171 switch (info->bw) { 4172 case RATE_INFO_BW_5: 4173 rate_flg = NL80211_RATE_INFO_5_MHZ_WIDTH; 4174 break; 4175 case RATE_INFO_BW_10: 4176 rate_flg = NL80211_RATE_INFO_10_MHZ_WIDTH; 4177 break; 4178 default: 4179 WARN_ON(1); 4180 /* fall through */ 4181 case RATE_INFO_BW_20: 4182 rate_flg = 0; 4183 break; 4184 case RATE_INFO_BW_40: 4185 rate_flg = NL80211_RATE_INFO_40_MHZ_WIDTH; 4186 break; 4187 case RATE_INFO_BW_80: 4188 rate_flg = NL80211_RATE_INFO_80_MHZ_WIDTH; 4189 break; 4190 case RATE_INFO_BW_160: 4191 rate_flg = NL80211_RATE_INFO_160_MHZ_WIDTH; 4192 break; 4193 } 4194 4195 if (rate_flg && nla_put_flag(msg, rate_flg)) 4196 return false; 4197 4198 if (info->flags & RATE_INFO_FLAGS_MCS) { 4199 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs)) 4200 return false; 4201 if (info->flags & RATE_INFO_FLAGS_SHORT_GI && 4202 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI)) 4203 return false; 4204 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) { 4205 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs)) 4206 return false; 4207 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss)) 4208 return false; 4209 if (info->flags & RATE_INFO_FLAGS_SHORT_GI && 4210 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI)) 4211 return false; 4212 } 4213 4214 nla_nest_end(msg, rate); 4215 return true; 4216 } 4217 4218 static bool nl80211_put_signal(struct sk_buff *msg, u8 mask, s8 *signal, 4219 int id) 4220 { 4221 void *attr; 4222 int i = 0; 4223 4224 if (!mask) 4225 return true; 4226 4227 attr = nla_nest_start(msg, id); 4228 if (!attr) 4229 return false; 4230 4231 for (i = 0; i < IEEE80211_MAX_CHAINS; i++) { 4232 if (!(mask & BIT(i))) 4233 continue; 4234 4235 if (nla_put_u8(msg, i, signal[i])) 4236 return false; 4237 } 4238 4239 nla_nest_end(msg, attr); 4240 4241 return true; 4242 } 4243 4244 static int nl80211_send_station(struct sk_buff *msg, u32 cmd, u32 portid, 4245 u32 seq, int flags, 4246 struct cfg80211_registered_device *rdev, 4247 struct net_device *dev, 4248 const u8 *mac_addr, struct station_info *sinfo) 4249 { 4250 void *hdr; 4251 struct nlattr *sinfoattr, *bss_param; 4252 4253 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 4254 if (!hdr) 4255 return -1; 4256 4257 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 4258 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) || 4259 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation)) 4260 goto nla_put_failure; 4261 4262 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO); 4263 if (!sinfoattr) 4264 goto nla_put_failure; 4265 4266 #define PUT_SINFO(attr, memb, type) do { \ 4267 BUILD_BUG_ON(sizeof(type) == sizeof(u64)); \ 4268 if (sinfo->filled & (1ULL << NL80211_STA_INFO_ ## attr) && \ 4269 nla_put_ ## type(msg, NL80211_STA_INFO_ ## attr, \ 4270 sinfo->memb)) \ 4271 goto nla_put_failure; \ 4272 } while (0) 4273 #define PUT_SINFO_U64(attr, memb) do { \ 4274 if (sinfo->filled & (1ULL << NL80211_STA_INFO_ ## attr) && \ 4275 nla_put_u64_64bit(msg, NL80211_STA_INFO_ ## attr, \ 4276 sinfo->memb, NL80211_STA_INFO_PAD)) \ 4277 goto nla_put_failure; \ 4278 } while (0) 4279 4280 PUT_SINFO(CONNECTED_TIME, connected_time, u32); 4281 PUT_SINFO(INACTIVE_TIME, inactive_time, u32); 4282 4283 if (sinfo->filled & (BIT(NL80211_STA_INFO_RX_BYTES) | 4284 BIT(NL80211_STA_INFO_RX_BYTES64)) && 4285 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES, 4286 (u32)sinfo->rx_bytes)) 4287 goto nla_put_failure; 4288 4289 if (sinfo->filled & (BIT(NL80211_STA_INFO_TX_BYTES) | 4290 BIT(NL80211_STA_INFO_TX_BYTES64)) && 4291 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES, 4292 (u32)sinfo->tx_bytes)) 4293 goto nla_put_failure; 4294 4295 PUT_SINFO_U64(RX_BYTES64, rx_bytes); 4296 PUT_SINFO_U64(TX_BYTES64, tx_bytes); 4297 PUT_SINFO(LLID, llid, u16); 4298 PUT_SINFO(PLID, plid, u16); 4299 PUT_SINFO(PLINK_STATE, plink_state, u8); 4300 PUT_SINFO_U64(RX_DURATION, rx_duration); 4301 4302 switch (rdev->wiphy.signal_type) { 4303 case CFG80211_SIGNAL_TYPE_MBM: 4304 PUT_SINFO(SIGNAL, signal, u8); 4305 PUT_SINFO(SIGNAL_AVG, signal_avg, u8); 4306 break; 4307 default: 4308 break; 4309 } 4310 if (sinfo->filled & BIT(NL80211_STA_INFO_CHAIN_SIGNAL)) { 4311 if (!nl80211_put_signal(msg, sinfo->chains, 4312 sinfo->chain_signal, 4313 NL80211_STA_INFO_CHAIN_SIGNAL)) 4314 goto nla_put_failure; 4315 } 4316 if (sinfo->filled & BIT(NL80211_STA_INFO_CHAIN_SIGNAL_AVG)) { 4317 if (!nl80211_put_signal(msg, sinfo->chains, 4318 sinfo->chain_signal_avg, 4319 NL80211_STA_INFO_CHAIN_SIGNAL_AVG)) 4320 goto nla_put_failure; 4321 } 4322 if (sinfo->filled & BIT(NL80211_STA_INFO_TX_BITRATE)) { 4323 if (!nl80211_put_sta_rate(msg, &sinfo->txrate, 4324 NL80211_STA_INFO_TX_BITRATE)) 4325 goto nla_put_failure; 4326 } 4327 if (sinfo->filled & BIT(NL80211_STA_INFO_RX_BITRATE)) { 4328 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate, 4329 NL80211_STA_INFO_RX_BITRATE)) 4330 goto nla_put_failure; 4331 } 4332 4333 PUT_SINFO(RX_PACKETS, rx_packets, u32); 4334 PUT_SINFO(TX_PACKETS, tx_packets, u32); 4335 PUT_SINFO(TX_RETRIES, tx_retries, u32); 4336 PUT_SINFO(TX_FAILED, tx_failed, u32); 4337 PUT_SINFO(EXPECTED_THROUGHPUT, expected_throughput, u32); 4338 PUT_SINFO(BEACON_LOSS, beacon_loss_count, u32); 4339 PUT_SINFO(LOCAL_PM, local_pm, u32); 4340 PUT_SINFO(PEER_PM, peer_pm, u32); 4341 PUT_SINFO(NONPEER_PM, nonpeer_pm, u32); 4342 4343 if (sinfo->filled & BIT(NL80211_STA_INFO_BSS_PARAM)) { 4344 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM); 4345 if (!bss_param) 4346 goto nla_put_failure; 4347 4348 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) && 4349 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) || 4350 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) && 4351 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) || 4352 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) && 4353 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) || 4354 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD, 4355 sinfo->bss_param.dtim_period) || 4356 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL, 4357 sinfo->bss_param.beacon_interval)) 4358 goto nla_put_failure; 4359 4360 nla_nest_end(msg, bss_param); 4361 } 4362 if ((sinfo->filled & BIT(NL80211_STA_INFO_STA_FLAGS)) && 4363 nla_put(msg, NL80211_STA_INFO_STA_FLAGS, 4364 sizeof(struct nl80211_sta_flag_update), 4365 &sinfo->sta_flags)) 4366 goto nla_put_failure; 4367 4368 PUT_SINFO_U64(T_OFFSET, t_offset); 4369 PUT_SINFO_U64(RX_DROP_MISC, rx_dropped_misc); 4370 PUT_SINFO_U64(BEACON_RX, rx_beacon); 4371 PUT_SINFO(BEACON_SIGNAL_AVG, rx_beacon_signal_avg, u8); 4372 4373 #undef PUT_SINFO 4374 #undef PUT_SINFO_U64 4375 4376 if (sinfo->filled & BIT(NL80211_STA_INFO_TID_STATS)) { 4377 struct nlattr *tidsattr; 4378 int tid; 4379 4380 tidsattr = nla_nest_start(msg, NL80211_STA_INFO_TID_STATS); 4381 if (!tidsattr) 4382 goto nla_put_failure; 4383 4384 for (tid = 0; tid < IEEE80211_NUM_TIDS + 1; tid++) { 4385 struct cfg80211_tid_stats *tidstats; 4386 struct nlattr *tidattr; 4387 4388 tidstats = &sinfo->pertid[tid]; 4389 4390 if (!tidstats->filled) 4391 continue; 4392 4393 tidattr = nla_nest_start(msg, tid + 1); 4394 if (!tidattr) 4395 goto nla_put_failure; 4396 4397 #define PUT_TIDVAL_U64(attr, memb) do { \ 4398 if (tidstats->filled & BIT(NL80211_TID_STATS_ ## attr) && \ 4399 nla_put_u64_64bit(msg, NL80211_TID_STATS_ ## attr, \ 4400 tidstats->memb, NL80211_TID_STATS_PAD)) \ 4401 goto nla_put_failure; \ 4402 } while (0) 4403 4404 PUT_TIDVAL_U64(RX_MSDU, rx_msdu); 4405 PUT_TIDVAL_U64(TX_MSDU, tx_msdu); 4406 PUT_TIDVAL_U64(TX_MSDU_RETRIES, tx_msdu_retries); 4407 PUT_TIDVAL_U64(TX_MSDU_FAILED, tx_msdu_failed); 4408 4409 #undef PUT_TIDVAL_U64 4410 nla_nest_end(msg, tidattr); 4411 } 4412 4413 nla_nest_end(msg, tidsattr); 4414 } 4415 4416 nla_nest_end(msg, sinfoattr); 4417 4418 if (sinfo->assoc_req_ies_len && 4419 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len, 4420 sinfo->assoc_req_ies)) 4421 goto nla_put_failure; 4422 4423 genlmsg_end(msg, hdr); 4424 return 0; 4425 4426 nla_put_failure: 4427 genlmsg_cancel(msg, hdr); 4428 return -EMSGSIZE; 4429 } 4430 4431 static int nl80211_dump_station(struct sk_buff *skb, 4432 struct netlink_callback *cb) 4433 { 4434 struct station_info sinfo; 4435 struct cfg80211_registered_device *rdev; 4436 struct wireless_dev *wdev; 4437 u8 mac_addr[ETH_ALEN]; 4438 int sta_idx = cb->args[2]; 4439 int err; 4440 4441 rtnl_lock(); 4442 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 4443 if (err) 4444 goto out_err; 4445 4446 if (!wdev->netdev) { 4447 err = -EINVAL; 4448 goto out_err; 4449 } 4450 4451 if (!rdev->ops->dump_station) { 4452 err = -EOPNOTSUPP; 4453 goto out_err; 4454 } 4455 4456 while (1) { 4457 memset(&sinfo, 0, sizeof(sinfo)); 4458 err = rdev_dump_station(rdev, wdev->netdev, sta_idx, 4459 mac_addr, &sinfo); 4460 if (err == -ENOENT) 4461 break; 4462 if (err) 4463 goto out_err; 4464 4465 if (nl80211_send_station(skb, NL80211_CMD_NEW_STATION, 4466 NETLINK_CB(cb->skb).portid, 4467 cb->nlh->nlmsg_seq, NLM_F_MULTI, 4468 rdev, wdev->netdev, mac_addr, 4469 &sinfo) < 0) 4470 goto out; 4471 4472 sta_idx++; 4473 } 4474 4475 out: 4476 cb->args[2] = sta_idx; 4477 err = skb->len; 4478 out_err: 4479 rtnl_unlock(); 4480 4481 return err; 4482 } 4483 4484 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info) 4485 { 4486 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 4487 struct net_device *dev = info->user_ptr[1]; 4488 struct station_info sinfo; 4489 struct sk_buff *msg; 4490 u8 *mac_addr = NULL; 4491 int err; 4492 4493 memset(&sinfo, 0, sizeof(sinfo)); 4494 4495 if (!info->attrs[NL80211_ATTR_MAC]) 4496 return -EINVAL; 4497 4498 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 4499 4500 if (!rdev->ops->get_station) 4501 return -EOPNOTSUPP; 4502 4503 err = rdev_get_station(rdev, dev, mac_addr, &sinfo); 4504 if (err) 4505 return err; 4506 4507 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 4508 if (!msg) 4509 return -ENOMEM; 4510 4511 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION, 4512 info->snd_portid, info->snd_seq, 0, 4513 rdev, dev, mac_addr, &sinfo) < 0) { 4514 nlmsg_free(msg); 4515 return -ENOBUFS; 4516 } 4517 4518 return genlmsg_reply(msg, info); 4519 } 4520 4521 int cfg80211_check_station_change(struct wiphy *wiphy, 4522 struct station_parameters *params, 4523 enum cfg80211_station_type statype) 4524 { 4525 if (params->listen_interval != -1 && 4526 statype != CFG80211_STA_AP_CLIENT_UNASSOC) 4527 return -EINVAL; 4528 4529 if (params->support_p2p_ps != -1 && 4530 statype != CFG80211_STA_AP_CLIENT_UNASSOC) 4531 return -EINVAL; 4532 4533 if (params->aid && 4534 !(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) && 4535 statype != CFG80211_STA_AP_CLIENT_UNASSOC) 4536 return -EINVAL; 4537 4538 /* When you run into this, adjust the code below for the new flag */ 4539 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7); 4540 4541 switch (statype) { 4542 case CFG80211_STA_MESH_PEER_KERNEL: 4543 case CFG80211_STA_MESH_PEER_USER: 4544 /* 4545 * No ignoring the TDLS flag here -- the userspace mesh 4546 * code doesn't have the bug of including TDLS in the 4547 * mask everywhere. 4548 */ 4549 if (params->sta_flags_mask & 4550 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4551 BIT(NL80211_STA_FLAG_MFP) | 4552 BIT(NL80211_STA_FLAG_AUTHORIZED))) 4553 return -EINVAL; 4554 break; 4555 case CFG80211_STA_TDLS_PEER_SETUP: 4556 case CFG80211_STA_TDLS_PEER_ACTIVE: 4557 if (!(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))) 4558 return -EINVAL; 4559 /* ignore since it can't change */ 4560 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER); 4561 break; 4562 default: 4563 /* disallow mesh-specific things */ 4564 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION) 4565 return -EINVAL; 4566 if (params->local_pm) 4567 return -EINVAL; 4568 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE) 4569 return -EINVAL; 4570 } 4571 4572 if (statype != CFG80211_STA_TDLS_PEER_SETUP && 4573 statype != CFG80211_STA_TDLS_PEER_ACTIVE) { 4574 /* TDLS can't be set, ... */ 4575 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) 4576 return -EINVAL; 4577 /* 4578 * ... but don't bother the driver with it. This works around 4579 * a hostapd/wpa_supplicant issue -- it always includes the 4580 * TLDS_PEER flag in the mask even for AP mode. 4581 */ 4582 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER); 4583 } 4584 4585 if (statype != CFG80211_STA_TDLS_PEER_SETUP && 4586 statype != CFG80211_STA_AP_CLIENT_UNASSOC) { 4587 /* reject other things that can't change */ 4588 if (params->sta_modify_mask & STATION_PARAM_APPLY_UAPSD) 4589 return -EINVAL; 4590 if (params->sta_modify_mask & STATION_PARAM_APPLY_CAPABILITY) 4591 return -EINVAL; 4592 if (params->supported_rates) 4593 return -EINVAL; 4594 if (params->ext_capab || params->ht_capa || params->vht_capa) 4595 return -EINVAL; 4596 } 4597 4598 if (statype != CFG80211_STA_AP_CLIENT && 4599 statype != CFG80211_STA_AP_CLIENT_UNASSOC) { 4600 if (params->vlan) 4601 return -EINVAL; 4602 } 4603 4604 switch (statype) { 4605 case CFG80211_STA_AP_MLME_CLIENT: 4606 /* Use this only for authorizing/unauthorizing a station */ 4607 if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED))) 4608 return -EOPNOTSUPP; 4609 break; 4610 case CFG80211_STA_AP_CLIENT: 4611 case CFG80211_STA_AP_CLIENT_UNASSOC: 4612 /* accept only the listed bits */ 4613 if (params->sta_flags_mask & 4614 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) | 4615 BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4616 BIT(NL80211_STA_FLAG_ASSOCIATED) | 4617 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) | 4618 BIT(NL80211_STA_FLAG_WME) | 4619 BIT(NL80211_STA_FLAG_MFP))) 4620 return -EINVAL; 4621 4622 /* but authenticated/associated only if driver handles it */ 4623 if (!(wiphy->features & NL80211_FEATURE_FULL_AP_CLIENT_STATE) && 4624 params->sta_flags_mask & 4625 (BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4626 BIT(NL80211_STA_FLAG_ASSOCIATED))) 4627 return -EINVAL; 4628 break; 4629 case CFG80211_STA_IBSS: 4630 case CFG80211_STA_AP_STA: 4631 /* reject any changes other than AUTHORIZED */ 4632 if (params->sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED)) 4633 return -EINVAL; 4634 break; 4635 case CFG80211_STA_TDLS_PEER_SETUP: 4636 /* reject any changes other than AUTHORIZED or WME */ 4637 if (params->sta_flags_mask & ~(BIT(NL80211_STA_FLAG_AUTHORIZED) | 4638 BIT(NL80211_STA_FLAG_WME))) 4639 return -EINVAL; 4640 /* force (at least) rates when authorizing */ 4641 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED) && 4642 !params->supported_rates) 4643 return -EINVAL; 4644 break; 4645 case CFG80211_STA_TDLS_PEER_ACTIVE: 4646 /* reject any changes */ 4647 return -EINVAL; 4648 case CFG80211_STA_MESH_PEER_KERNEL: 4649 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE) 4650 return -EINVAL; 4651 break; 4652 case CFG80211_STA_MESH_PEER_USER: 4653 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION && 4654 params->plink_action != NL80211_PLINK_ACTION_BLOCK) 4655 return -EINVAL; 4656 break; 4657 } 4658 4659 /* 4660 * Older kernel versions ignored this attribute entirely, so don't 4661 * reject attempts to update it but mark it as unused instead so the 4662 * driver won't look at the data. 4663 */ 4664 if (statype != CFG80211_STA_AP_CLIENT_UNASSOC && 4665 statype != CFG80211_STA_TDLS_PEER_SETUP) 4666 params->opmode_notif_used = false; 4667 4668 return 0; 4669 } 4670 EXPORT_SYMBOL(cfg80211_check_station_change); 4671 4672 /* 4673 * Get vlan interface making sure it is running and on the right wiphy. 4674 */ 4675 static struct net_device *get_vlan(struct genl_info *info, 4676 struct cfg80211_registered_device *rdev) 4677 { 4678 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN]; 4679 struct net_device *v; 4680 int ret; 4681 4682 if (!vlanattr) 4683 return NULL; 4684 4685 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr)); 4686 if (!v) 4687 return ERR_PTR(-ENODEV); 4688 4689 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) { 4690 ret = -EINVAL; 4691 goto error; 4692 } 4693 4694 if (v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN && 4695 v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 4696 v->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) { 4697 ret = -EINVAL; 4698 goto error; 4699 } 4700 4701 if (!netif_running(v)) { 4702 ret = -ENETDOWN; 4703 goto error; 4704 } 4705 4706 return v; 4707 error: 4708 dev_put(v); 4709 return ERR_PTR(ret); 4710 } 4711 4712 static const struct nla_policy 4713 nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] = { 4714 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 }, 4715 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 }, 4716 }; 4717 4718 static int nl80211_parse_sta_wme(struct genl_info *info, 4719 struct station_parameters *params) 4720 { 4721 struct nlattr *tb[NL80211_STA_WME_MAX + 1]; 4722 struct nlattr *nla; 4723 int err; 4724 4725 /* parse WME attributes if present */ 4726 if (!info->attrs[NL80211_ATTR_STA_WME]) 4727 return 0; 4728 4729 nla = info->attrs[NL80211_ATTR_STA_WME]; 4730 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla, 4731 nl80211_sta_wme_policy); 4732 if (err) 4733 return err; 4734 4735 if (tb[NL80211_STA_WME_UAPSD_QUEUES]) 4736 params->uapsd_queues = nla_get_u8( 4737 tb[NL80211_STA_WME_UAPSD_QUEUES]); 4738 if (params->uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK) 4739 return -EINVAL; 4740 4741 if (tb[NL80211_STA_WME_MAX_SP]) 4742 params->max_sp = nla_get_u8(tb[NL80211_STA_WME_MAX_SP]); 4743 4744 if (params->max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK) 4745 return -EINVAL; 4746 4747 params->sta_modify_mask |= STATION_PARAM_APPLY_UAPSD; 4748 4749 return 0; 4750 } 4751 4752 static int nl80211_parse_sta_channel_info(struct genl_info *info, 4753 struct station_parameters *params) 4754 { 4755 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]) { 4756 params->supported_channels = 4757 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]); 4758 params->supported_channels_len = 4759 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]); 4760 /* 4761 * Need to include at least one (first channel, number of 4762 * channels) tuple for each subband, and must have proper 4763 * tuples for the rest of the data as well. 4764 */ 4765 if (params->supported_channels_len < 2) 4766 return -EINVAL; 4767 if (params->supported_channels_len % 2) 4768 return -EINVAL; 4769 } 4770 4771 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]) { 4772 params->supported_oper_classes = 4773 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]); 4774 params->supported_oper_classes_len = 4775 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]); 4776 /* 4777 * The value of the Length field of the Supported Operating 4778 * Classes element is between 2 and 253. 4779 */ 4780 if (params->supported_oper_classes_len < 2 || 4781 params->supported_oper_classes_len > 253) 4782 return -EINVAL; 4783 } 4784 return 0; 4785 } 4786 4787 static int nl80211_set_station_tdls(struct genl_info *info, 4788 struct station_parameters *params) 4789 { 4790 int err; 4791 /* Dummy STA entry gets updated once the peer capabilities are known */ 4792 if (info->attrs[NL80211_ATTR_PEER_AID]) 4793 params->aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]); 4794 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) 4795 params->ht_capa = 4796 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]); 4797 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) 4798 params->vht_capa = 4799 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]); 4800 4801 err = nl80211_parse_sta_channel_info(info, params); 4802 if (err) 4803 return err; 4804 4805 return nl80211_parse_sta_wme(info, params); 4806 } 4807 4808 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info) 4809 { 4810 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 4811 struct net_device *dev = info->user_ptr[1]; 4812 struct station_parameters params; 4813 u8 *mac_addr; 4814 int err; 4815 4816 memset(¶ms, 0, sizeof(params)); 4817 4818 if (!rdev->ops->change_station) 4819 return -EOPNOTSUPP; 4820 4821 /* 4822 * AID and listen_interval properties can be set only for unassociated 4823 * station. Include these parameters here and will check them in 4824 * cfg80211_check_station_change(). 4825 */ 4826 if (info->attrs[NL80211_ATTR_STA_AID]) 4827 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]); 4828 4829 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]) 4830 params.listen_interval = 4831 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]); 4832 else 4833 params.listen_interval = -1; 4834 4835 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]) { 4836 u8 tmp; 4837 4838 tmp = nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]); 4839 if (tmp >= NUM_NL80211_P2P_PS_STATUS) 4840 return -EINVAL; 4841 4842 params.support_p2p_ps = tmp; 4843 } else { 4844 params.support_p2p_ps = -1; 4845 } 4846 4847 if (!info->attrs[NL80211_ATTR_MAC]) 4848 return -EINVAL; 4849 4850 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 4851 4852 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) { 4853 params.supported_rates = 4854 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]); 4855 params.supported_rates_len = 4856 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]); 4857 } 4858 4859 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) { 4860 params.capability = 4861 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]); 4862 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY; 4863 } 4864 4865 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) { 4866 params.ext_capab = 4867 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]); 4868 params.ext_capab_len = 4869 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]); 4870 } 4871 4872 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, ¶ms)) 4873 return -EINVAL; 4874 4875 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) { 4876 params.plink_action = 4877 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]); 4878 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS) 4879 return -EINVAL; 4880 } 4881 4882 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE]) { 4883 params.plink_state = 4884 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]); 4885 if (params.plink_state >= NUM_NL80211_PLINK_STATES) 4886 return -EINVAL; 4887 if (info->attrs[NL80211_ATTR_MESH_PEER_AID]) { 4888 params.peer_aid = nla_get_u16( 4889 info->attrs[NL80211_ATTR_MESH_PEER_AID]); 4890 if (params.peer_aid > IEEE80211_MAX_AID) 4891 return -EINVAL; 4892 } 4893 params.sta_modify_mask |= STATION_PARAM_APPLY_PLINK_STATE; 4894 } 4895 4896 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]) { 4897 enum nl80211_mesh_power_mode pm = nla_get_u32( 4898 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]); 4899 4900 if (pm <= NL80211_MESH_POWER_UNKNOWN || 4901 pm > NL80211_MESH_POWER_MAX) 4902 return -EINVAL; 4903 4904 params.local_pm = pm; 4905 } 4906 4907 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) { 4908 params.opmode_notif_used = true; 4909 params.opmode_notif = 4910 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]); 4911 } 4912 4913 /* Include parameters for TDLS peer (will check later) */ 4914 err = nl80211_set_station_tdls(info, ¶ms); 4915 if (err) 4916 return err; 4917 4918 params.vlan = get_vlan(info, rdev); 4919 if (IS_ERR(params.vlan)) 4920 return PTR_ERR(params.vlan); 4921 4922 switch (dev->ieee80211_ptr->iftype) { 4923 case NL80211_IFTYPE_AP: 4924 case NL80211_IFTYPE_AP_VLAN: 4925 case NL80211_IFTYPE_P2P_GO: 4926 case NL80211_IFTYPE_P2P_CLIENT: 4927 case NL80211_IFTYPE_STATION: 4928 case NL80211_IFTYPE_ADHOC: 4929 case NL80211_IFTYPE_MESH_POINT: 4930 break; 4931 default: 4932 err = -EOPNOTSUPP; 4933 goto out_put_vlan; 4934 } 4935 4936 /* driver will call cfg80211_check_station_change() */ 4937 err = rdev_change_station(rdev, dev, mac_addr, ¶ms); 4938 4939 out_put_vlan: 4940 if (params.vlan) 4941 dev_put(params.vlan); 4942 4943 return err; 4944 } 4945 4946 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info) 4947 { 4948 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 4949 int err; 4950 struct net_device *dev = info->user_ptr[1]; 4951 struct station_parameters params; 4952 u8 *mac_addr = NULL; 4953 u32 auth_assoc = BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4954 BIT(NL80211_STA_FLAG_ASSOCIATED); 4955 4956 memset(¶ms, 0, sizeof(params)); 4957 4958 if (!rdev->ops->add_station) 4959 return -EOPNOTSUPP; 4960 4961 if (!info->attrs[NL80211_ATTR_MAC]) 4962 return -EINVAL; 4963 4964 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]) 4965 return -EINVAL; 4966 4967 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) 4968 return -EINVAL; 4969 4970 if (!info->attrs[NL80211_ATTR_STA_AID] && 4971 !info->attrs[NL80211_ATTR_PEER_AID]) 4972 return -EINVAL; 4973 4974 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 4975 params.supported_rates = 4976 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]); 4977 params.supported_rates_len = 4978 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]); 4979 params.listen_interval = 4980 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]); 4981 4982 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]) { 4983 u8 tmp; 4984 4985 tmp = nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]); 4986 if (tmp >= NUM_NL80211_P2P_PS_STATUS) 4987 return -EINVAL; 4988 4989 params.support_p2p_ps = tmp; 4990 } else { 4991 /* 4992 * if not specified, assume it's supported for P2P GO interface, 4993 * and is NOT supported for AP interface 4994 */ 4995 params.support_p2p_ps = 4996 dev->ieee80211_ptr->iftype == NL80211_IFTYPE_P2P_GO; 4997 } 4998 4999 if (info->attrs[NL80211_ATTR_PEER_AID]) 5000 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]); 5001 else 5002 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]); 5003 if (!params.aid || params.aid > IEEE80211_MAX_AID) 5004 return -EINVAL; 5005 5006 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) { 5007 params.capability = 5008 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]); 5009 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY; 5010 } 5011 5012 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) { 5013 params.ext_capab = 5014 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]); 5015 params.ext_capab_len = 5016 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]); 5017 } 5018 5019 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) 5020 params.ht_capa = 5021 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]); 5022 5023 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) 5024 params.vht_capa = 5025 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]); 5026 5027 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) { 5028 params.opmode_notif_used = true; 5029 params.opmode_notif = 5030 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]); 5031 } 5032 5033 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) { 5034 params.plink_action = 5035 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]); 5036 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS) 5037 return -EINVAL; 5038 } 5039 5040 err = nl80211_parse_sta_channel_info(info, ¶ms); 5041 if (err) 5042 return err; 5043 5044 err = nl80211_parse_sta_wme(info, ¶ms); 5045 if (err) 5046 return err; 5047 5048 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, ¶ms)) 5049 return -EINVAL; 5050 5051 /* HT/VHT requires QoS, but if we don't have that just ignore HT/VHT 5052 * as userspace might just pass through the capabilities from the IEs 5053 * directly, rather than enforcing this restriction and returning an 5054 * error in this case. 5055 */ 5056 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME))) { 5057 params.ht_capa = NULL; 5058 params.vht_capa = NULL; 5059 } 5060 5061 /* When you run into this, adjust the code below for the new flag */ 5062 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7); 5063 5064 switch (dev->ieee80211_ptr->iftype) { 5065 case NL80211_IFTYPE_AP: 5066 case NL80211_IFTYPE_AP_VLAN: 5067 case NL80211_IFTYPE_P2P_GO: 5068 /* ignore WME attributes if iface/sta is not capable */ 5069 if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) || 5070 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME))) 5071 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD; 5072 5073 /* TDLS peers cannot be added */ 5074 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) || 5075 info->attrs[NL80211_ATTR_PEER_AID]) 5076 return -EINVAL; 5077 /* but don't bother the driver with it */ 5078 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER); 5079 5080 /* allow authenticated/associated only if driver handles it */ 5081 if (!(rdev->wiphy.features & 5082 NL80211_FEATURE_FULL_AP_CLIENT_STATE) && 5083 params.sta_flags_mask & auth_assoc) 5084 return -EINVAL; 5085 5086 /* Older userspace, or userspace wanting to be compatible with 5087 * !NL80211_FEATURE_FULL_AP_CLIENT_STATE, will not set the auth 5088 * and assoc flags in the mask, but assumes the station will be 5089 * added as associated anyway since this was the required driver 5090 * behaviour before NL80211_FEATURE_FULL_AP_CLIENT_STATE was 5091 * introduced. 5092 * In order to not bother drivers with this quirk in the API 5093 * set the flags in both the mask and set for new stations in 5094 * this case. 5095 */ 5096 if (!(params.sta_flags_mask & auth_assoc)) { 5097 params.sta_flags_mask |= auth_assoc; 5098 params.sta_flags_set |= auth_assoc; 5099 } 5100 5101 /* must be last in here for error handling */ 5102 params.vlan = get_vlan(info, rdev); 5103 if (IS_ERR(params.vlan)) 5104 return PTR_ERR(params.vlan); 5105 break; 5106 case NL80211_IFTYPE_MESH_POINT: 5107 /* ignore uAPSD data */ 5108 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD; 5109 5110 /* associated is disallowed */ 5111 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED)) 5112 return -EINVAL; 5113 /* TDLS peers cannot be added */ 5114 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) || 5115 info->attrs[NL80211_ATTR_PEER_AID]) 5116 return -EINVAL; 5117 break; 5118 case NL80211_IFTYPE_STATION: 5119 case NL80211_IFTYPE_P2P_CLIENT: 5120 /* ignore uAPSD data */ 5121 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD; 5122 5123 /* these are disallowed */ 5124 if (params.sta_flags_mask & 5125 (BIT(NL80211_STA_FLAG_ASSOCIATED) | 5126 BIT(NL80211_STA_FLAG_AUTHENTICATED))) 5127 return -EINVAL; 5128 /* Only TDLS peers can be added */ 5129 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))) 5130 return -EINVAL; 5131 /* Can only add if TDLS ... */ 5132 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS)) 5133 return -EOPNOTSUPP; 5134 /* ... with external setup is supported */ 5135 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP)) 5136 return -EOPNOTSUPP; 5137 /* 5138 * Older wpa_supplicant versions always mark the TDLS peer 5139 * as authorized, but it shouldn't yet be. 5140 */ 5141 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_AUTHORIZED); 5142 break; 5143 default: 5144 return -EOPNOTSUPP; 5145 } 5146 5147 /* be aware of params.vlan when changing code here */ 5148 5149 err = rdev_add_station(rdev, dev, mac_addr, ¶ms); 5150 5151 if (params.vlan) 5152 dev_put(params.vlan); 5153 return err; 5154 } 5155 5156 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info) 5157 { 5158 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5159 struct net_device *dev = info->user_ptr[1]; 5160 struct station_del_parameters params; 5161 5162 memset(¶ms, 0, sizeof(params)); 5163 5164 if (info->attrs[NL80211_ATTR_MAC]) 5165 params.mac = nla_data(info->attrs[NL80211_ATTR_MAC]); 5166 5167 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 5168 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN && 5169 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT && 5170 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 5171 return -EINVAL; 5172 5173 if (!rdev->ops->del_station) 5174 return -EOPNOTSUPP; 5175 5176 if (info->attrs[NL80211_ATTR_MGMT_SUBTYPE]) { 5177 params.subtype = 5178 nla_get_u8(info->attrs[NL80211_ATTR_MGMT_SUBTYPE]); 5179 if (params.subtype != IEEE80211_STYPE_DISASSOC >> 4 && 5180 params.subtype != IEEE80211_STYPE_DEAUTH >> 4) 5181 return -EINVAL; 5182 } else { 5183 /* Default to Deauthentication frame */ 5184 params.subtype = IEEE80211_STYPE_DEAUTH >> 4; 5185 } 5186 5187 if (info->attrs[NL80211_ATTR_REASON_CODE]) { 5188 params.reason_code = 5189 nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]); 5190 if (params.reason_code == 0) 5191 return -EINVAL; /* 0 is reserved */ 5192 } else { 5193 /* Default to reason code 2 */ 5194 params.reason_code = WLAN_REASON_PREV_AUTH_NOT_VALID; 5195 } 5196 5197 return rdev_del_station(rdev, dev, ¶ms); 5198 } 5199 5200 static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq, 5201 int flags, struct net_device *dev, 5202 u8 *dst, u8 *next_hop, 5203 struct mpath_info *pinfo) 5204 { 5205 void *hdr; 5206 struct nlattr *pinfoattr; 5207 5208 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_MPATH); 5209 if (!hdr) 5210 return -1; 5211 5212 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 5213 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) || 5214 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) || 5215 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation)) 5216 goto nla_put_failure; 5217 5218 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO); 5219 if (!pinfoattr) 5220 goto nla_put_failure; 5221 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) && 5222 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN, 5223 pinfo->frame_qlen)) 5224 goto nla_put_failure; 5225 if (((pinfo->filled & MPATH_INFO_SN) && 5226 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) || 5227 ((pinfo->filled & MPATH_INFO_METRIC) && 5228 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC, 5229 pinfo->metric)) || 5230 ((pinfo->filled & MPATH_INFO_EXPTIME) && 5231 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME, 5232 pinfo->exptime)) || 5233 ((pinfo->filled & MPATH_INFO_FLAGS) && 5234 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS, 5235 pinfo->flags)) || 5236 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) && 5237 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT, 5238 pinfo->discovery_timeout)) || 5239 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) && 5240 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES, 5241 pinfo->discovery_retries))) 5242 goto nla_put_failure; 5243 5244 nla_nest_end(msg, pinfoattr); 5245 5246 genlmsg_end(msg, hdr); 5247 return 0; 5248 5249 nla_put_failure: 5250 genlmsg_cancel(msg, hdr); 5251 return -EMSGSIZE; 5252 } 5253 5254 static int nl80211_dump_mpath(struct sk_buff *skb, 5255 struct netlink_callback *cb) 5256 { 5257 struct mpath_info pinfo; 5258 struct cfg80211_registered_device *rdev; 5259 struct wireless_dev *wdev; 5260 u8 dst[ETH_ALEN]; 5261 u8 next_hop[ETH_ALEN]; 5262 int path_idx = cb->args[2]; 5263 int err; 5264 5265 rtnl_lock(); 5266 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 5267 if (err) 5268 goto out_err; 5269 5270 if (!rdev->ops->dump_mpath) { 5271 err = -EOPNOTSUPP; 5272 goto out_err; 5273 } 5274 5275 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) { 5276 err = -EOPNOTSUPP; 5277 goto out_err; 5278 } 5279 5280 while (1) { 5281 err = rdev_dump_mpath(rdev, wdev->netdev, path_idx, dst, 5282 next_hop, &pinfo); 5283 if (err == -ENOENT) 5284 break; 5285 if (err) 5286 goto out_err; 5287 5288 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid, 5289 cb->nlh->nlmsg_seq, NLM_F_MULTI, 5290 wdev->netdev, dst, next_hop, 5291 &pinfo) < 0) 5292 goto out; 5293 5294 path_idx++; 5295 } 5296 5297 out: 5298 cb->args[2] = path_idx; 5299 err = skb->len; 5300 out_err: 5301 rtnl_unlock(); 5302 return err; 5303 } 5304 5305 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info) 5306 { 5307 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5308 int err; 5309 struct net_device *dev = info->user_ptr[1]; 5310 struct mpath_info pinfo; 5311 struct sk_buff *msg; 5312 u8 *dst = NULL; 5313 u8 next_hop[ETH_ALEN]; 5314 5315 memset(&pinfo, 0, sizeof(pinfo)); 5316 5317 if (!info->attrs[NL80211_ATTR_MAC]) 5318 return -EINVAL; 5319 5320 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5321 5322 if (!rdev->ops->get_mpath) 5323 return -EOPNOTSUPP; 5324 5325 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) 5326 return -EOPNOTSUPP; 5327 5328 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo); 5329 if (err) 5330 return err; 5331 5332 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 5333 if (!msg) 5334 return -ENOMEM; 5335 5336 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0, 5337 dev, dst, next_hop, &pinfo) < 0) { 5338 nlmsg_free(msg); 5339 return -ENOBUFS; 5340 } 5341 5342 return genlmsg_reply(msg, info); 5343 } 5344 5345 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info) 5346 { 5347 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5348 struct net_device *dev = info->user_ptr[1]; 5349 u8 *dst = NULL; 5350 u8 *next_hop = NULL; 5351 5352 if (!info->attrs[NL80211_ATTR_MAC]) 5353 return -EINVAL; 5354 5355 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]) 5356 return -EINVAL; 5357 5358 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5359 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]); 5360 5361 if (!rdev->ops->change_mpath) 5362 return -EOPNOTSUPP; 5363 5364 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) 5365 return -EOPNOTSUPP; 5366 5367 return rdev_change_mpath(rdev, dev, dst, next_hop); 5368 } 5369 5370 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info) 5371 { 5372 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5373 struct net_device *dev = info->user_ptr[1]; 5374 u8 *dst = NULL; 5375 u8 *next_hop = NULL; 5376 5377 if (!info->attrs[NL80211_ATTR_MAC]) 5378 return -EINVAL; 5379 5380 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]) 5381 return -EINVAL; 5382 5383 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5384 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]); 5385 5386 if (!rdev->ops->add_mpath) 5387 return -EOPNOTSUPP; 5388 5389 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) 5390 return -EOPNOTSUPP; 5391 5392 return rdev_add_mpath(rdev, dev, dst, next_hop); 5393 } 5394 5395 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info) 5396 { 5397 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5398 struct net_device *dev = info->user_ptr[1]; 5399 u8 *dst = NULL; 5400 5401 if (info->attrs[NL80211_ATTR_MAC]) 5402 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5403 5404 if (!rdev->ops->del_mpath) 5405 return -EOPNOTSUPP; 5406 5407 return rdev_del_mpath(rdev, dev, dst); 5408 } 5409 5410 static int nl80211_get_mpp(struct sk_buff *skb, struct genl_info *info) 5411 { 5412 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5413 int err; 5414 struct net_device *dev = info->user_ptr[1]; 5415 struct mpath_info pinfo; 5416 struct sk_buff *msg; 5417 u8 *dst = NULL; 5418 u8 mpp[ETH_ALEN]; 5419 5420 memset(&pinfo, 0, sizeof(pinfo)); 5421 5422 if (!info->attrs[NL80211_ATTR_MAC]) 5423 return -EINVAL; 5424 5425 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5426 5427 if (!rdev->ops->get_mpp) 5428 return -EOPNOTSUPP; 5429 5430 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) 5431 return -EOPNOTSUPP; 5432 5433 err = rdev_get_mpp(rdev, dev, dst, mpp, &pinfo); 5434 if (err) 5435 return err; 5436 5437 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 5438 if (!msg) 5439 return -ENOMEM; 5440 5441 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0, 5442 dev, dst, mpp, &pinfo) < 0) { 5443 nlmsg_free(msg); 5444 return -ENOBUFS; 5445 } 5446 5447 return genlmsg_reply(msg, info); 5448 } 5449 5450 static int nl80211_dump_mpp(struct sk_buff *skb, 5451 struct netlink_callback *cb) 5452 { 5453 struct mpath_info pinfo; 5454 struct cfg80211_registered_device *rdev; 5455 struct wireless_dev *wdev; 5456 u8 dst[ETH_ALEN]; 5457 u8 mpp[ETH_ALEN]; 5458 int path_idx = cb->args[2]; 5459 int err; 5460 5461 rtnl_lock(); 5462 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 5463 if (err) 5464 goto out_err; 5465 5466 if (!rdev->ops->dump_mpp) { 5467 err = -EOPNOTSUPP; 5468 goto out_err; 5469 } 5470 5471 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) { 5472 err = -EOPNOTSUPP; 5473 goto out_err; 5474 } 5475 5476 while (1) { 5477 err = rdev_dump_mpp(rdev, wdev->netdev, path_idx, dst, 5478 mpp, &pinfo); 5479 if (err == -ENOENT) 5480 break; 5481 if (err) 5482 goto out_err; 5483 5484 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid, 5485 cb->nlh->nlmsg_seq, NLM_F_MULTI, 5486 wdev->netdev, dst, mpp, 5487 &pinfo) < 0) 5488 goto out; 5489 5490 path_idx++; 5491 } 5492 5493 out: 5494 cb->args[2] = path_idx; 5495 err = skb->len; 5496 out_err: 5497 rtnl_unlock(); 5498 return err; 5499 } 5500 5501 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info) 5502 { 5503 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5504 struct net_device *dev = info->user_ptr[1]; 5505 struct wireless_dev *wdev = dev->ieee80211_ptr; 5506 struct bss_parameters params; 5507 int err; 5508 5509 memset(¶ms, 0, sizeof(params)); 5510 /* default to not changing parameters */ 5511 params.use_cts_prot = -1; 5512 params.use_short_preamble = -1; 5513 params.use_short_slot_time = -1; 5514 params.ap_isolate = -1; 5515 params.ht_opmode = -1; 5516 params.p2p_ctwindow = -1; 5517 params.p2p_opp_ps = -1; 5518 5519 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT]) 5520 params.use_cts_prot = 5521 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]); 5522 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]) 5523 params.use_short_preamble = 5524 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]); 5525 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]) 5526 params.use_short_slot_time = 5527 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]); 5528 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) { 5529 params.basic_rates = 5530 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 5531 params.basic_rates_len = 5532 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 5533 } 5534 if (info->attrs[NL80211_ATTR_AP_ISOLATE]) 5535 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]); 5536 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE]) 5537 params.ht_opmode = 5538 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]); 5539 5540 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) { 5541 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 5542 return -EINVAL; 5543 params.p2p_ctwindow = 5544 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]); 5545 if (params.p2p_ctwindow < 0) 5546 return -EINVAL; 5547 if (params.p2p_ctwindow != 0 && 5548 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN)) 5549 return -EINVAL; 5550 } 5551 5552 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) { 5553 u8 tmp; 5554 5555 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 5556 return -EINVAL; 5557 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]); 5558 if (tmp > 1) 5559 return -EINVAL; 5560 params.p2p_opp_ps = tmp; 5561 if (params.p2p_opp_ps && 5562 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS)) 5563 return -EINVAL; 5564 } 5565 5566 if (!rdev->ops->change_bss) 5567 return -EOPNOTSUPP; 5568 5569 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 5570 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 5571 return -EOPNOTSUPP; 5572 5573 wdev_lock(wdev); 5574 err = rdev_change_bss(rdev, dev, ¶ms); 5575 wdev_unlock(wdev); 5576 5577 return err; 5578 } 5579 5580 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info) 5581 { 5582 char *data = NULL; 5583 bool is_indoor; 5584 enum nl80211_user_reg_hint_type user_reg_hint_type; 5585 u32 owner_nlportid; 5586 5587 /* 5588 * You should only get this when cfg80211 hasn't yet initialized 5589 * completely when built-in to the kernel right between the time 5590 * window between nl80211_init() and regulatory_init(), if that is 5591 * even possible. 5592 */ 5593 if (unlikely(!rcu_access_pointer(cfg80211_regdomain))) 5594 return -EINPROGRESS; 5595 5596 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]) 5597 user_reg_hint_type = 5598 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]); 5599 else 5600 user_reg_hint_type = NL80211_USER_REG_HINT_USER; 5601 5602 switch (user_reg_hint_type) { 5603 case NL80211_USER_REG_HINT_USER: 5604 case NL80211_USER_REG_HINT_CELL_BASE: 5605 if (!info->attrs[NL80211_ATTR_REG_ALPHA2]) 5606 return -EINVAL; 5607 5608 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]); 5609 return regulatory_hint_user(data, user_reg_hint_type); 5610 case NL80211_USER_REG_HINT_INDOOR: 5611 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) { 5612 owner_nlportid = info->snd_portid; 5613 is_indoor = !!info->attrs[NL80211_ATTR_REG_INDOOR]; 5614 } else { 5615 owner_nlportid = 0; 5616 is_indoor = true; 5617 } 5618 5619 return regulatory_hint_indoor(is_indoor, owner_nlportid); 5620 default: 5621 return -EINVAL; 5622 } 5623 } 5624 5625 static int nl80211_get_mesh_config(struct sk_buff *skb, 5626 struct genl_info *info) 5627 { 5628 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5629 struct net_device *dev = info->user_ptr[1]; 5630 struct wireless_dev *wdev = dev->ieee80211_ptr; 5631 struct mesh_config cur_params; 5632 int err = 0; 5633 void *hdr; 5634 struct nlattr *pinfoattr; 5635 struct sk_buff *msg; 5636 5637 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) 5638 return -EOPNOTSUPP; 5639 5640 if (!rdev->ops->get_mesh_config) 5641 return -EOPNOTSUPP; 5642 5643 wdev_lock(wdev); 5644 /* If not connected, get default parameters */ 5645 if (!wdev->mesh_id_len) 5646 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params)); 5647 else 5648 err = rdev_get_mesh_config(rdev, dev, &cur_params); 5649 wdev_unlock(wdev); 5650 5651 if (err) 5652 return err; 5653 5654 /* Draw up a netlink message to send back */ 5655 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 5656 if (!msg) 5657 return -ENOMEM; 5658 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 5659 NL80211_CMD_GET_MESH_CONFIG); 5660 if (!hdr) 5661 goto out; 5662 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG); 5663 if (!pinfoattr) 5664 goto nla_put_failure; 5665 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 5666 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT, 5667 cur_params.dot11MeshRetryTimeout) || 5668 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT, 5669 cur_params.dot11MeshConfirmTimeout) || 5670 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT, 5671 cur_params.dot11MeshHoldingTimeout) || 5672 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS, 5673 cur_params.dot11MeshMaxPeerLinks) || 5674 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES, 5675 cur_params.dot11MeshMaxRetries) || 5676 nla_put_u8(msg, NL80211_MESHCONF_TTL, 5677 cur_params.dot11MeshTTL) || 5678 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL, 5679 cur_params.element_ttl) || 5680 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS, 5681 cur_params.auto_open_plinks) || 5682 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR, 5683 cur_params.dot11MeshNbrOffsetMaxNeighbor) || 5684 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES, 5685 cur_params.dot11MeshHWMPmaxPREQretries) || 5686 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME, 5687 cur_params.path_refresh_time) || 5688 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT, 5689 cur_params.min_discovery_timeout) || 5690 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT, 5691 cur_params.dot11MeshHWMPactivePathTimeout) || 5692 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL, 5693 cur_params.dot11MeshHWMPpreqMinInterval) || 5694 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL, 5695 cur_params.dot11MeshHWMPperrMinInterval) || 5696 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME, 5697 cur_params.dot11MeshHWMPnetDiameterTraversalTime) || 5698 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE, 5699 cur_params.dot11MeshHWMPRootMode) || 5700 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL, 5701 cur_params.dot11MeshHWMPRannInterval) || 5702 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS, 5703 cur_params.dot11MeshGateAnnouncementProtocol) || 5704 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING, 5705 cur_params.dot11MeshForwarding) || 5706 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD, 5707 cur_params.rssi_threshold) || 5708 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE, 5709 cur_params.ht_opmode) || 5710 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT, 5711 cur_params.dot11MeshHWMPactivePathToRootTimeout) || 5712 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL, 5713 cur_params.dot11MeshHWMProotInterval) || 5714 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL, 5715 cur_params.dot11MeshHWMPconfirmationInterval) || 5716 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE, 5717 cur_params.power_mode) || 5718 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW, 5719 cur_params.dot11MeshAwakeWindowDuration) || 5720 nla_put_u32(msg, NL80211_MESHCONF_PLINK_TIMEOUT, 5721 cur_params.plink_timeout)) 5722 goto nla_put_failure; 5723 nla_nest_end(msg, pinfoattr); 5724 genlmsg_end(msg, hdr); 5725 return genlmsg_reply(msg, info); 5726 5727 nla_put_failure: 5728 genlmsg_cancel(msg, hdr); 5729 out: 5730 nlmsg_free(msg); 5731 return -ENOBUFS; 5732 } 5733 5734 static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = { 5735 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 }, 5736 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 }, 5737 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 }, 5738 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 }, 5739 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 }, 5740 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 }, 5741 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 }, 5742 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 }, 5743 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 }, 5744 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 }, 5745 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 }, 5746 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 }, 5747 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 }, 5748 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 }, 5749 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 }, 5750 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 }, 5751 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 }, 5752 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 }, 5753 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 }, 5754 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 }, 5755 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 }, 5756 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 }, 5757 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 }, 5758 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 }, 5759 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 }, 5760 [NL80211_MESHCONF_POWER_MODE] = { .type = NLA_U32 }, 5761 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 }, 5762 [NL80211_MESHCONF_PLINK_TIMEOUT] = { .type = NLA_U32 }, 5763 }; 5764 5765 static const struct nla_policy 5766 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = { 5767 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 }, 5768 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 }, 5769 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 }, 5770 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG }, 5771 [NL80211_MESH_SETUP_AUTH_PROTOCOL] = { .type = NLA_U8 }, 5772 [NL80211_MESH_SETUP_USERSPACE_MPM] = { .type = NLA_FLAG }, 5773 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY, 5774 .len = IEEE80211_MAX_DATA_LEN }, 5775 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG }, 5776 }; 5777 5778 static int nl80211_check_bool(const struct nlattr *nla, u8 min, u8 max, bool *out) 5779 { 5780 u8 val = nla_get_u8(nla); 5781 if (val < min || val > max) 5782 return -EINVAL; 5783 *out = val; 5784 return 0; 5785 } 5786 5787 static int nl80211_check_u8(const struct nlattr *nla, u8 min, u8 max, u8 *out) 5788 { 5789 u8 val = nla_get_u8(nla); 5790 if (val < min || val > max) 5791 return -EINVAL; 5792 *out = val; 5793 return 0; 5794 } 5795 5796 static int nl80211_check_u16(const struct nlattr *nla, u16 min, u16 max, u16 *out) 5797 { 5798 u16 val = nla_get_u16(nla); 5799 if (val < min || val > max) 5800 return -EINVAL; 5801 *out = val; 5802 return 0; 5803 } 5804 5805 static int nl80211_check_u32(const struct nlattr *nla, u32 min, u32 max, u32 *out) 5806 { 5807 u32 val = nla_get_u32(nla); 5808 if (val < min || val > max) 5809 return -EINVAL; 5810 *out = val; 5811 return 0; 5812 } 5813 5814 static int nl80211_check_s32(const struct nlattr *nla, s32 min, s32 max, s32 *out) 5815 { 5816 s32 val = nla_get_s32(nla); 5817 if (val < min || val > max) 5818 return -EINVAL; 5819 *out = val; 5820 return 0; 5821 } 5822 5823 static int nl80211_check_power_mode(const struct nlattr *nla, 5824 enum nl80211_mesh_power_mode min, 5825 enum nl80211_mesh_power_mode max, 5826 enum nl80211_mesh_power_mode *out) 5827 { 5828 u32 val = nla_get_u32(nla); 5829 if (val < min || val > max) 5830 return -EINVAL; 5831 *out = val; 5832 return 0; 5833 } 5834 5835 static int nl80211_parse_mesh_config(struct genl_info *info, 5836 struct mesh_config *cfg, 5837 u32 *mask_out) 5838 { 5839 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1]; 5840 u32 mask = 0; 5841 u16 ht_opmode; 5842 5843 #define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, min, max, mask, attr, fn) \ 5844 do { \ 5845 if (tb[attr]) { \ 5846 if (fn(tb[attr], min, max, &cfg->param)) \ 5847 return -EINVAL; \ 5848 mask |= (1 << (attr - 1)); \ 5849 } \ 5850 } while (0) 5851 5852 if (!info->attrs[NL80211_ATTR_MESH_CONFIG]) 5853 return -EINVAL; 5854 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX, 5855 info->attrs[NL80211_ATTR_MESH_CONFIG], 5856 nl80211_meshconf_params_policy)) 5857 return -EINVAL; 5858 5859 /* This makes sure that there aren't more than 32 mesh config 5860 * parameters (otherwise our bitfield scheme would not work.) */ 5861 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32); 5862 5863 /* Fill in the params struct */ 5864 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, 1, 255, 5865 mask, NL80211_MESHCONF_RETRY_TIMEOUT, 5866 nl80211_check_u16); 5867 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, 1, 255, 5868 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, 5869 nl80211_check_u16); 5870 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, 1, 255, 5871 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, 5872 nl80211_check_u16); 5873 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, 0, 255, 5874 mask, NL80211_MESHCONF_MAX_PEER_LINKS, 5875 nl80211_check_u16); 5876 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, 0, 16, 5877 mask, NL80211_MESHCONF_MAX_RETRIES, 5878 nl80211_check_u8); 5879 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, 1, 255, 5880 mask, NL80211_MESHCONF_TTL, nl80211_check_u8); 5881 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, 1, 255, 5882 mask, NL80211_MESHCONF_ELEMENT_TTL, 5883 nl80211_check_u8); 5884 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, 0, 1, 5885 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, 5886 nl80211_check_bool); 5887 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor, 5888 1, 255, mask, 5889 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR, 5890 nl80211_check_u32); 5891 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, 0, 255, 5892 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES, 5893 nl80211_check_u8); 5894 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, 1, 65535, 5895 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, 5896 nl80211_check_u32); 5897 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, 1, 65535, 5898 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT, 5899 nl80211_check_u16); 5900 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout, 5901 1, 65535, mask, 5902 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT, 5903 nl80211_check_u32); 5904 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval, 5905 1, 65535, mask, 5906 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL, 5907 nl80211_check_u16); 5908 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval, 5909 1, 65535, mask, 5910 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL, 5911 nl80211_check_u16); 5912 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, 5913 dot11MeshHWMPnetDiameterTraversalTime, 5914 1, 65535, mask, 5915 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME, 5916 nl80211_check_u16); 5917 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, 0, 4, 5918 mask, NL80211_MESHCONF_HWMP_ROOTMODE, 5919 nl80211_check_u8); 5920 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, 1, 65535, 5921 mask, NL80211_MESHCONF_HWMP_RANN_INTERVAL, 5922 nl80211_check_u16); 5923 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, 5924 dot11MeshGateAnnouncementProtocol, 0, 1, 5925 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS, 5926 nl80211_check_bool); 5927 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, 0, 1, 5928 mask, NL80211_MESHCONF_FORWARDING, 5929 nl80211_check_bool); 5930 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, -255, 0, 5931 mask, NL80211_MESHCONF_RSSI_THRESHOLD, 5932 nl80211_check_s32); 5933 /* 5934 * Check HT operation mode based on 5935 * IEEE 802.11 2012 8.4.2.59 HT Operation element. 5936 */ 5937 if (tb[NL80211_MESHCONF_HT_OPMODE]) { 5938 ht_opmode = nla_get_u16(tb[NL80211_MESHCONF_HT_OPMODE]); 5939 5940 if (ht_opmode & ~(IEEE80211_HT_OP_MODE_PROTECTION | 5941 IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT | 5942 IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT)) 5943 return -EINVAL; 5944 5945 if ((ht_opmode & IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT) && 5946 (ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT)) 5947 return -EINVAL; 5948 5949 switch (ht_opmode & IEEE80211_HT_OP_MODE_PROTECTION) { 5950 case IEEE80211_HT_OP_MODE_PROTECTION_NONE: 5951 case IEEE80211_HT_OP_MODE_PROTECTION_20MHZ: 5952 if (ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT) 5953 return -EINVAL; 5954 break; 5955 case IEEE80211_HT_OP_MODE_PROTECTION_NONMEMBER: 5956 case IEEE80211_HT_OP_MODE_PROTECTION_NONHT_MIXED: 5957 if (!(ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT)) 5958 return -EINVAL; 5959 break; 5960 } 5961 cfg->ht_opmode = ht_opmode; 5962 mask |= (1 << (NL80211_MESHCONF_HT_OPMODE - 1)); 5963 } 5964 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout, 5965 1, 65535, mask, 5966 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT, 5967 nl80211_check_u32); 5968 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, 1, 65535, 5969 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL, 5970 nl80211_check_u16); 5971 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, 5972 dot11MeshHWMPconfirmationInterval, 5973 1, 65535, mask, 5974 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL, 5975 nl80211_check_u16); 5976 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode, 5977 NL80211_MESH_POWER_ACTIVE, 5978 NL80211_MESH_POWER_MAX, 5979 mask, NL80211_MESHCONF_POWER_MODE, 5980 nl80211_check_power_mode); 5981 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration, 5982 0, 65535, mask, 5983 NL80211_MESHCONF_AWAKE_WINDOW, nl80211_check_u16); 5984 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, plink_timeout, 0, 0xffffffff, 5985 mask, NL80211_MESHCONF_PLINK_TIMEOUT, 5986 nl80211_check_u32); 5987 if (mask_out) 5988 *mask_out = mask; 5989 5990 return 0; 5991 5992 #undef FILL_IN_MESH_PARAM_IF_SET 5993 } 5994 5995 static int nl80211_parse_mesh_setup(struct genl_info *info, 5996 struct mesh_setup *setup) 5997 { 5998 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5999 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1]; 6000 6001 if (!info->attrs[NL80211_ATTR_MESH_SETUP]) 6002 return -EINVAL; 6003 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX, 6004 info->attrs[NL80211_ATTR_MESH_SETUP], 6005 nl80211_mesh_setup_params_policy)) 6006 return -EINVAL; 6007 6008 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC]) 6009 setup->sync_method = 6010 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ? 6011 IEEE80211_SYNC_METHOD_VENDOR : 6012 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET; 6013 6014 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL]) 6015 setup->path_sel_proto = 6016 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ? 6017 IEEE80211_PATH_PROTOCOL_VENDOR : 6018 IEEE80211_PATH_PROTOCOL_HWMP; 6019 6020 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC]) 6021 setup->path_metric = 6022 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ? 6023 IEEE80211_PATH_METRIC_VENDOR : 6024 IEEE80211_PATH_METRIC_AIRTIME; 6025 6026 if (tb[NL80211_MESH_SETUP_IE]) { 6027 struct nlattr *ieattr = 6028 tb[NL80211_MESH_SETUP_IE]; 6029 if (!is_valid_ie_attr(ieattr)) 6030 return -EINVAL; 6031 setup->ie = nla_data(ieattr); 6032 setup->ie_len = nla_len(ieattr); 6033 } 6034 if (tb[NL80211_MESH_SETUP_USERSPACE_MPM] && 6035 !(rdev->wiphy.features & NL80211_FEATURE_USERSPACE_MPM)) 6036 return -EINVAL; 6037 setup->user_mpm = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_MPM]); 6038 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]); 6039 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]); 6040 if (setup->is_secure) 6041 setup->user_mpm = true; 6042 6043 if (tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]) { 6044 if (!setup->user_mpm) 6045 return -EINVAL; 6046 setup->auth_id = 6047 nla_get_u8(tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]); 6048 } 6049 6050 return 0; 6051 } 6052 6053 static int nl80211_update_mesh_config(struct sk_buff *skb, 6054 struct genl_info *info) 6055 { 6056 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 6057 struct net_device *dev = info->user_ptr[1]; 6058 struct wireless_dev *wdev = dev->ieee80211_ptr; 6059 struct mesh_config cfg; 6060 u32 mask; 6061 int err; 6062 6063 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) 6064 return -EOPNOTSUPP; 6065 6066 if (!rdev->ops->update_mesh_config) 6067 return -EOPNOTSUPP; 6068 6069 err = nl80211_parse_mesh_config(info, &cfg, &mask); 6070 if (err) 6071 return err; 6072 6073 wdev_lock(wdev); 6074 if (!wdev->mesh_id_len) 6075 err = -ENOLINK; 6076 6077 if (!err) 6078 err = rdev_update_mesh_config(rdev, dev, mask, &cfg); 6079 6080 wdev_unlock(wdev); 6081 6082 return err; 6083 } 6084 6085 static int nl80211_put_regdom(const struct ieee80211_regdomain *regdom, 6086 struct sk_buff *msg) 6087 { 6088 struct nlattr *nl_reg_rules; 6089 unsigned int i; 6090 6091 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) || 6092 (regdom->dfs_region && 6093 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region))) 6094 goto nla_put_failure; 6095 6096 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES); 6097 if (!nl_reg_rules) 6098 goto nla_put_failure; 6099 6100 for (i = 0; i < regdom->n_reg_rules; i++) { 6101 struct nlattr *nl_reg_rule; 6102 const struct ieee80211_reg_rule *reg_rule; 6103 const struct ieee80211_freq_range *freq_range; 6104 const struct ieee80211_power_rule *power_rule; 6105 unsigned int max_bandwidth_khz; 6106 6107 reg_rule = ®dom->reg_rules[i]; 6108 freq_range = ®_rule->freq_range; 6109 power_rule = ®_rule->power_rule; 6110 6111 nl_reg_rule = nla_nest_start(msg, i); 6112 if (!nl_reg_rule) 6113 goto nla_put_failure; 6114 6115 max_bandwidth_khz = freq_range->max_bandwidth_khz; 6116 if (!max_bandwidth_khz) 6117 max_bandwidth_khz = reg_get_max_bandwidth(regdom, 6118 reg_rule); 6119 6120 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS, 6121 reg_rule->flags) || 6122 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START, 6123 freq_range->start_freq_khz) || 6124 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END, 6125 freq_range->end_freq_khz) || 6126 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW, 6127 max_bandwidth_khz) || 6128 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN, 6129 power_rule->max_antenna_gain) || 6130 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP, 6131 power_rule->max_eirp) || 6132 nla_put_u32(msg, NL80211_ATTR_DFS_CAC_TIME, 6133 reg_rule->dfs_cac_ms)) 6134 goto nla_put_failure; 6135 6136 nla_nest_end(msg, nl_reg_rule); 6137 } 6138 6139 nla_nest_end(msg, nl_reg_rules); 6140 return 0; 6141 6142 nla_put_failure: 6143 return -EMSGSIZE; 6144 } 6145 6146 static int nl80211_get_reg_do(struct sk_buff *skb, struct genl_info *info) 6147 { 6148 const struct ieee80211_regdomain *regdom = NULL; 6149 struct cfg80211_registered_device *rdev; 6150 struct wiphy *wiphy = NULL; 6151 struct sk_buff *msg; 6152 void *hdr; 6153 6154 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 6155 if (!msg) 6156 return -ENOBUFS; 6157 6158 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 6159 NL80211_CMD_GET_REG); 6160 if (!hdr) 6161 goto put_failure; 6162 6163 if (info->attrs[NL80211_ATTR_WIPHY]) { 6164 bool self_managed; 6165 6166 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info); 6167 if (IS_ERR(rdev)) { 6168 nlmsg_free(msg); 6169 return PTR_ERR(rdev); 6170 } 6171 6172 wiphy = &rdev->wiphy; 6173 self_managed = wiphy->regulatory_flags & 6174 REGULATORY_WIPHY_SELF_MANAGED; 6175 regdom = get_wiphy_regdom(wiphy); 6176 6177 /* a self-managed-reg device must have a private regdom */ 6178 if (WARN_ON(!regdom && self_managed)) { 6179 nlmsg_free(msg); 6180 return -EINVAL; 6181 } 6182 6183 if (regdom && 6184 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy))) 6185 goto nla_put_failure; 6186 } 6187 6188 if (!wiphy && reg_last_request_cell_base() && 6189 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE, 6190 NL80211_USER_REG_HINT_CELL_BASE)) 6191 goto nla_put_failure; 6192 6193 rcu_read_lock(); 6194 6195 if (!regdom) 6196 regdom = rcu_dereference(cfg80211_regdomain); 6197 6198 if (nl80211_put_regdom(regdom, msg)) 6199 goto nla_put_failure_rcu; 6200 6201 rcu_read_unlock(); 6202 6203 genlmsg_end(msg, hdr); 6204 return genlmsg_reply(msg, info); 6205 6206 nla_put_failure_rcu: 6207 rcu_read_unlock(); 6208 nla_put_failure: 6209 genlmsg_cancel(msg, hdr); 6210 put_failure: 6211 nlmsg_free(msg); 6212 return -EMSGSIZE; 6213 } 6214 6215 static int nl80211_send_regdom(struct sk_buff *msg, struct netlink_callback *cb, 6216 u32 seq, int flags, struct wiphy *wiphy, 6217 const struct ieee80211_regdomain *regdom) 6218 { 6219 void *hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags, 6220 NL80211_CMD_GET_REG); 6221 6222 if (!hdr) 6223 return -1; 6224 6225 genl_dump_check_consistent(cb, hdr, &nl80211_fam); 6226 6227 if (nl80211_put_regdom(regdom, msg)) 6228 goto nla_put_failure; 6229 6230 if (!wiphy && reg_last_request_cell_base() && 6231 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE, 6232 NL80211_USER_REG_HINT_CELL_BASE)) 6233 goto nla_put_failure; 6234 6235 if (wiphy && 6236 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy))) 6237 goto nla_put_failure; 6238 6239 if (wiphy && wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED && 6240 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG)) 6241 goto nla_put_failure; 6242 6243 genlmsg_end(msg, hdr); 6244 return 0; 6245 6246 nla_put_failure: 6247 genlmsg_cancel(msg, hdr); 6248 return -EMSGSIZE; 6249 } 6250 6251 static int nl80211_get_reg_dump(struct sk_buff *skb, 6252 struct netlink_callback *cb) 6253 { 6254 const struct ieee80211_regdomain *regdom = NULL; 6255 struct cfg80211_registered_device *rdev; 6256 int err, reg_idx, start = cb->args[2]; 6257 6258 rtnl_lock(); 6259 6260 if (cfg80211_regdomain && start == 0) { 6261 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq, 6262 NLM_F_MULTI, NULL, 6263 rtnl_dereference(cfg80211_regdomain)); 6264 if (err < 0) 6265 goto out_err; 6266 } 6267 6268 /* the global regdom is idx 0 */ 6269 reg_idx = 1; 6270 list_for_each_entry(rdev, &cfg80211_rdev_list, list) { 6271 regdom = get_wiphy_regdom(&rdev->wiphy); 6272 if (!regdom) 6273 continue; 6274 6275 if (++reg_idx <= start) 6276 continue; 6277 6278 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq, 6279 NLM_F_MULTI, &rdev->wiphy, regdom); 6280 if (err < 0) { 6281 reg_idx--; 6282 break; 6283 } 6284 } 6285 6286 cb->args[2] = reg_idx; 6287 err = skb->len; 6288 out_err: 6289 rtnl_unlock(); 6290 return err; 6291 } 6292 6293 #ifdef CONFIG_CFG80211_CRDA_SUPPORT 6294 static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = { 6295 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 }, 6296 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 }, 6297 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 }, 6298 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 }, 6299 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 }, 6300 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 }, 6301 [NL80211_ATTR_DFS_CAC_TIME] = { .type = NLA_U32 }, 6302 }; 6303 6304 static int parse_reg_rule(struct nlattr *tb[], 6305 struct ieee80211_reg_rule *reg_rule) 6306 { 6307 struct ieee80211_freq_range *freq_range = ®_rule->freq_range; 6308 struct ieee80211_power_rule *power_rule = ®_rule->power_rule; 6309 6310 if (!tb[NL80211_ATTR_REG_RULE_FLAGS]) 6311 return -EINVAL; 6312 if (!tb[NL80211_ATTR_FREQ_RANGE_START]) 6313 return -EINVAL; 6314 if (!tb[NL80211_ATTR_FREQ_RANGE_END]) 6315 return -EINVAL; 6316 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]) 6317 return -EINVAL; 6318 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]) 6319 return -EINVAL; 6320 6321 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]); 6322 6323 freq_range->start_freq_khz = 6324 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]); 6325 freq_range->end_freq_khz = 6326 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]); 6327 freq_range->max_bandwidth_khz = 6328 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]); 6329 6330 power_rule->max_eirp = 6331 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]); 6332 6333 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]) 6334 power_rule->max_antenna_gain = 6335 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]); 6336 6337 if (tb[NL80211_ATTR_DFS_CAC_TIME]) 6338 reg_rule->dfs_cac_ms = 6339 nla_get_u32(tb[NL80211_ATTR_DFS_CAC_TIME]); 6340 6341 return 0; 6342 } 6343 6344 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info) 6345 { 6346 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1]; 6347 struct nlattr *nl_reg_rule; 6348 char *alpha2; 6349 int rem_reg_rules, r; 6350 u32 num_rules = 0, rule_idx = 0, size_of_regd; 6351 enum nl80211_dfs_regions dfs_region = NL80211_DFS_UNSET; 6352 struct ieee80211_regdomain *rd; 6353 6354 if (!info->attrs[NL80211_ATTR_REG_ALPHA2]) 6355 return -EINVAL; 6356 6357 if (!info->attrs[NL80211_ATTR_REG_RULES]) 6358 return -EINVAL; 6359 6360 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]); 6361 6362 if (info->attrs[NL80211_ATTR_DFS_REGION]) 6363 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]); 6364 6365 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES], 6366 rem_reg_rules) { 6367 num_rules++; 6368 if (num_rules > NL80211_MAX_SUPP_REG_RULES) 6369 return -EINVAL; 6370 } 6371 6372 if (!reg_is_valid_request(alpha2)) 6373 return -EINVAL; 6374 6375 size_of_regd = sizeof(struct ieee80211_regdomain) + 6376 num_rules * sizeof(struct ieee80211_reg_rule); 6377 6378 rd = kzalloc(size_of_regd, GFP_KERNEL); 6379 if (!rd) 6380 return -ENOMEM; 6381 6382 rd->n_reg_rules = num_rules; 6383 rd->alpha2[0] = alpha2[0]; 6384 rd->alpha2[1] = alpha2[1]; 6385 6386 /* 6387 * Disable DFS master mode if the DFS region was 6388 * not supported or known on this kernel. 6389 */ 6390 if (reg_supported_dfs_region(dfs_region)) 6391 rd->dfs_region = dfs_region; 6392 6393 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES], 6394 rem_reg_rules) { 6395 r = nla_parse_nested(tb, NL80211_REG_RULE_ATTR_MAX, 6396 nl_reg_rule, reg_rule_policy); 6397 if (r) 6398 goto bad_reg; 6399 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]); 6400 if (r) 6401 goto bad_reg; 6402 6403 rule_idx++; 6404 6405 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) { 6406 r = -EINVAL; 6407 goto bad_reg; 6408 } 6409 } 6410 6411 /* set_regdom takes ownership of rd */ 6412 return set_regdom(rd, REGD_SOURCE_CRDA); 6413 bad_reg: 6414 kfree(rd); 6415 return r; 6416 } 6417 #endif /* CONFIG_CFG80211_CRDA_SUPPORT */ 6418 6419 static int validate_scan_freqs(struct nlattr *freqs) 6420 { 6421 struct nlattr *attr1, *attr2; 6422 int n_channels = 0, tmp1, tmp2; 6423 6424 nla_for_each_nested(attr1, freqs, tmp1) { 6425 n_channels++; 6426 /* 6427 * Some hardware has a limited channel list for 6428 * scanning, and it is pretty much nonsensical 6429 * to scan for a channel twice, so disallow that 6430 * and don't require drivers to check that the 6431 * channel list they get isn't longer than what 6432 * they can scan, as long as they can scan all 6433 * the channels they registered at once. 6434 */ 6435 nla_for_each_nested(attr2, freqs, tmp2) 6436 if (attr1 != attr2 && 6437 nla_get_u32(attr1) == nla_get_u32(attr2)) 6438 return 0; 6439 } 6440 6441 return n_channels; 6442 } 6443 6444 static bool is_band_valid(struct wiphy *wiphy, enum nl80211_band b) 6445 { 6446 return b < NUM_NL80211_BANDS && wiphy->bands[b]; 6447 } 6448 6449 static int parse_bss_select(struct nlattr *nla, struct wiphy *wiphy, 6450 struct cfg80211_bss_selection *bss_select) 6451 { 6452 struct nlattr *attr[NL80211_BSS_SELECT_ATTR_MAX + 1]; 6453 struct nlattr *nest; 6454 int err; 6455 bool found = false; 6456 int i; 6457 6458 /* only process one nested attribute */ 6459 nest = nla_data(nla); 6460 if (!nla_ok(nest, nla_len(nest))) 6461 return -EINVAL; 6462 6463 err = nla_parse_nested(attr, NL80211_BSS_SELECT_ATTR_MAX, nest, 6464 nl80211_bss_select_policy); 6465 if (err) 6466 return err; 6467 6468 /* only one attribute may be given */ 6469 for (i = 0; i <= NL80211_BSS_SELECT_ATTR_MAX; i++) { 6470 if (attr[i]) { 6471 if (found) 6472 return -EINVAL; 6473 found = true; 6474 } 6475 } 6476 6477 bss_select->behaviour = __NL80211_BSS_SELECT_ATTR_INVALID; 6478 6479 if (attr[NL80211_BSS_SELECT_ATTR_RSSI]) 6480 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI; 6481 6482 if (attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]) { 6483 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_BAND_PREF; 6484 bss_select->param.band_pref = 6485 nla_get_u32(attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]); 6486 if (!is_band_valid(wiphy, bss_select->param.band_pref)) 6487 return -EINVAL; 6488 } 6489 6490 if (attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]) { 6491 struct nl80211_bss_select_rssi_adjust *adj_param; 6492 6493 adj_param = nla_data(attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]); 6494 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI_ADJUST; 6495 bss_select->param.adjust.band = adj_param->band; 6496 bss_select->param.adjust.delta = adj_param->delta; 6497 if (!is_band_valid(wiphy, bss_select->param.adjust.band)) 6498 return -EINVAL; 6499 } 6500 6501 /* user-space did not provide behaviour attribute */ 6502 if (bss_select->behaviour == __NL80211_BSS_SELECT_ATTR_INVALID) 6503 return -EINVAL; 6504 6505 if (!(wiphy->bss_select_support & BIT(bss_select->behaviour))) 6506 return -EINVAL; 6507 6508 return 0; 6509 } 6510 6511 static int nl80211_parse_random_mac(struct nlattr **attrs, 6512 u8 *mac_addr, u8 *mac_addr_mask) 6513 { 6514 int i; 6515 6516 if (!attrs[NL80211_ATTR_MAC] && !attrs[NL80211_ATTR_MAC_MASK]) { 6517 eth_zero_addr(mac_addr); 6518 eth_zero_addr(mac_addr_mask); 6519 mac_addr[0] = 0x2; 6520 mac_addr_mask[0] = 0x3; 6521 6522 return 0; 6523 } 6524 6525 /* need both or none */ 6526 if (!attrs[NL80211_ATTR_MAC] || !attrs[NL80211_ATTR_MAC_MASK]) 6527 return -EINVAL; 6528 6529 memcpy(mac_addr, nla_data(attrs[NL80211_ATTR_MAC]), ETH_ALEN); 6530 memcpy(mac_addr_mask, nla_data(attrs[NL80211_ATTR_MAC_MASK]), ETH_ALEN); 6531 6532 /* don't allow or configure an mcast address */ 6533 if (!is_multicast_ether_addr(mac_addr_mask) || 6534 is_multicast_ether_addr(mac_addr)) 6535 return -EINVAL; 6536 6537 /* 6538 * allow users to pass a MAC address that has bits set outside 6539 * of the mask, but don't bother drivers with having to deal 6540 * with such bits 6541 */ 6542 for (i = 0; i < ETH_ALEN; i++) 6543 mac_addr[i] &= mac_addr_mask[i]; 6544 6545 return 0; 6546 } 6547 6548 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info) 6549 { 6550 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 6551 struct wireless_dev *wdev = info->user_ptr[1]; 6552 struct cfg80211_scan_request *request; 6553 struct nlattr *attr; 6554 struct wiphy *wiphy; 6555 int err, tmp, n_ssids = 0, n_channels, i; 6556 size_t ie_len; 6557 6558 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 6559 return -EINVAL; 6560 6561 wiphy = &rdev->wiphy; 6562 6563 if (wdev->iftype == NL80211_IFTYPE_NAN) 6564 return -EOPNOTSUPP; 6565 6566 if (!rdev->ops->scan) 6567 return -EOPNOTSUPP; 6568 6569 if (rdev->scan_req || rdev->scan_msg) { 6570 err = -EBUSY; 6571 goto unlock; 6572 } 6573 6574 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) { 6575 n_channels = validate_scan_freqs( 6576 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]); 6577 if (!n_channels) { 6578 err = -EINVAL; 6579 goto unlock; 6580 } 6581 } else { 6582 n_channels = ieee80211_get_num_supported_channels(wiphy); 6583 } 6584 6585 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) 6586 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) 6587 n_ssids++; 6588 6589 if (n_ssids > wiphy->max_scan_ssids) { 6590 err = -EINVAL; 6591 goto unlock; 6592 } 6593 6594 if (info->attrs[NL80211_ATTR_IE]) 6595 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 6596 else 6597 ie_len = 0; 6598 6599 if (ie_len > wiphy->max_scan_ie_len) { 6600 err = -EINVAL; 6601 goto unlock; 6602 } 6603 6604 request = kzalloc(sizeof(*request) 6605 + sizeof(*request->ssids) * n_ssids 6606 + sizeof(*request->channels) * n_channels 6607 + ie_len, GFP_KERNEL); 6608 if (!request) { 6609 err = -ENOMEM; 6610 goto unlock; 6611 } 6612 6613 if (n_ssids) 6614 request->ssids = (void *)&request->channels[n_channels]; 6615 request->n_ssids = n_ssids; 6616 if (ie_len) { 6617 if (n_ssids) 6618 request->ie = (void *)(request->ssids + n_ssids); 6619 else 6620 request->ie = (void *)(request->channels + n_channels); 6621 } 6622 6623 i = 0; 6624 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) { 6625 /* user specified, bail out if channel not found */ 6626 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) { 6627 struct ieee80211_channel *chan; 6628 6629 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr)); 6630 6631 if (!chan) { 6632 err = -EINVAL; 6633 goto out_free; 6634 } 6635 6636 /* ignore disabled channels */ 6637 if (chan->flags & IEEE80211_CHAN_DISABLED) 6638 continue; 6639 6640 request->channels[i] = chan; 6641 i++; 6642 } 6643 } else { 6644 enum nl80211_band band; 6645 6646 /* all channels */ 6647 for (band = 0; band < NUM_NL80211_BANDS; band++) { 6648 int j; 6649 6650 if (!wiphy->bands[band]) 6651 continue; 6652 for (j = 0; j < wiphy->bands[band]->n_channels; j++) { 6653 struct ieee80211_channel *chan; 6654 6655 chan = &wiphy->bands[band]->channels[j]; 6656 6657 if (chan->flags & IEEE80211_CHAN_DISABLED) 6658 continue; 6659 6660 request->channels[i] = chan; 6661 i++; 6662 } 6663 } 6664 } 6665 6666 if (!i) { 6667 err = -EINVAL; 6668 goto out_free; 6669 } 6670 6671 request->n_channels = i; 6672 6673 i = 0; 6674 if (n_ssids) { 6675 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) { 6676 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) { 6677 err = -EINVAL; 6678 goto out_free; 6679 } 6680 request->ssids[i].ssid_len = nla_len(attr); 6681 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr)); 6682 i++; 6683 } 6684 } 6685 6686 if (info->attrs[NL80211_ATTR_IE]) { 6687 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 6688 memcpy((void *)request->ie, 6689 nla_data(info->attrs[NL80211_ATTR_IE]), 6690 request->ie_len); 6691 } 6692 6693 for (i = 0; i < NUM_NL80211_BANDS; i++) 6694 if (wiphy->bands[i]) 6695 request->rates[i] = 6696 (1 << wiphy->bands[i]->n_bitrates) - 1; 6697 6698 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) { 6699 nla_for_each_nested(attr, 6700 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES], 6701 tmp) { 6702 enum nl80211_band band = nla_type(attr); 6703 6704 if (band < 0 || band >= NUM_NL80211_BANDS) { 6705 err = -EINVAL; 6706 goto out_free; 6707 } 6708 6709 if (!wiphy->bands[band]) 6710 continue; 6711 6712 err = ieee80211_get_ratemask(wiphy->bands[band], 6713 nla_data(attr), 6714 nla_len(attr), 6715 &request->rates[band]); 6716 if (err) 6717 goto out_free; 6718 } 6719 } 6720 6721 if (info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]) { 6722 if (!wiphy_ext_feature_isset(wiphy, 6723 NL80211_EXT_FEATURE_SET_SCAN_DWELL)) { 6724 err = -EOPNOTSUPP; 6725 goto out_free; 6726 } 6727 6728 request->duration = 6729 nla_get_u16(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]); 6730 request->duration_mandatory = 6731 nla_get_flag(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION_MANDATORY]); 6732 } 6733 6734 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) { 6735 request->flags = nla_get_u32( 6736 info->attrs[NL80211_ATTR_SCAN_FLAGS]); 6737 if ((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) && 6738 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) { 6739 err = -EOPNOTSUPP; 6740 goto out_free; 6741 } 6742 6743 if (request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) { 6744 if (!(wiphy->features & 6745 NL80211_FEATURE_SCAN_RANDOM_MAC_ADDR)) { 6746 err = -EOPNOTSUPP; 6747 goto out_free; 6748 } 6749 6750 if (wdev->current_bss) { 6751 err = -EOPNOTSUPP; 6752 goto out_free; 6753 } 6754 6755 err = nl80211_parse_random_mac(info->attrs, 6756 request->mac_addr, 6757 request->mac_addr_mask); 6758 if (err) 6759 goto out_free; 6760 } 6761 } 6762 6763 request->no_cck = 6764 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]); 6765 6766 /* Initial implementation used NL80211_ATTR_MAC to set the specific 6767 * BSSID to scan for. This was problematic because that same attribute 6768 * was already used for another purpose (local random MAC address). The 6769 * NL80211_ATTR_BSSID attribute was added to fix this. For backwards 6770 * compatibility with older userspace components, also use the 6771 * NL80211_ATTR_MAC value here if it can be determined to be used for 6772 * the specific BSSID use case instead of the random MAC address 6773 * (NL80211_ATTR_SCAN_FLAGS is used to enable random MAC address use). 6774 */ 6775 if (info->attrs[NL80211_ATTR_BSSID]) 6776 memcpy(request->bssid, 6777 nla_data(info->attrs[NL80211_ATTR_BSSID]), ETH_ALEN); 6778 else if (!(request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) && 6779 info->attrs[NL80211_ATTR_MAC]) 6780 memcpy(request->bssid, nla_data(info->attrs[NL80211_ATTR_MAC]), 6781 ETH_ALEN); 6782 else 6783 eth_broadcast_addr(request->bssid); 6784 6785 request->wdev = wdev; 6786 request->wiphy = &rdev->wiphy; 6787 request->scan_start = jiffies; 6788 6789 rdev->scan_req = request; 6790 err = rdev_scan(rdev, request); 6791 6792 if (!err) { 6793 nl80211_send_scan_start(rdev, wdev); 6794 if (wdev->netdev) 6795 dev_hold(wdev->netdev); 6796 } else { 6797 out_free: 6798 rdev->scan_req = NULL; 6799 kfree(request); 6800 } 6801 6802 unlock: 6803 return err; 6804 } 6805 6806 static int nl80211_abort_scan(struct sk_buff *skb, struct genl_info *info) 6807 { 6808 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 6809 struct wireless_dev *wdev = info->user_ptr[1]; 6810 6811 if (!rdev->ops->abort_scan) 6812 return -EOPNOTSUPP; 6813 6814 if (rdev->scan_msg) 6815 return 0; 6816 6817 if (!rdev->scan_req) 6818 return -ENOENT; 6819 6820 rdev_abort_scan(rdev, wdev); 6821 return 0; 6822 } 6823 6824 static int 6825 nl80211_parse_sched_scan_plans(struct wiphy *wiphy, int n_plans, 6826 struct cfg80211_sched_scan_request *request, 6827 struct nlattr **attrs) 6828 { 6829 int tmp, err, i = 0; 6830 struct nlattr *attr; 6831 6832 if (!attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) { 6833 u32 interval; 6834 6835 /* 6836 * If scan plans are not specified, 6837 * %NL80211_ATTR_SCHED_SCAN_INTERVAL will be specified. In this 6838 * case one scan plan will be set with the specified scan 6839 * interval and infinite number of iterations. 6840 */ 6841 interval = nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]); 6842 if (!interval) 6843 return -EINVAL; 6844 6845 request->scan_plans[0].interval = 6846 DIV_ROUND_UP(interval, MSEC_PER_SEC); 6847 if (!request->scan_plans[0].interval) 6848 return -EINVAL; 6849 6850 if (request->scan_plans[0].interval > 6851 wiphy->max_sched_scan_plan_interval) 6852 request->scan_plans[0].interval = 6853 wiphy->max_sched_scan_plan_interval; 6854 6855 return 0; 6856 } 6857 6858 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp) { 6859 struct nlattr *plan[NL80211_SCHED_SCAN_PLAN_MAX + 1]; 6860 6861 if (WARN_ON(i >= n_plans)) 6862 return -EINVAL; 6863 6864 err = nla_parse_nested(plan, NL80211_SCHED_SCAN_PLAN_MAX, 6865 attr, nl80211_plan_policy); 6866 if (err) 6867 return err; 6868 6869 if (!plan[NL80211_SCHED_SCAN_PLAN_INTERVAL]) 6870 return -EINVAL; 6871 6872 request->scan_plans[i].interval = 6873 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_INTERVAL]); 6874 if (!request->scan_plans[i].interval || 6875 request->scan_plans[i].interval > 6876 wiphy->max_sched_scan_plan_interval) 6877 return -EINVAL; 6878 6879 if (plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]) { 6880 request->scan_plans[i].iterations = 6881 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]); 6882 if (!request->scan_plans[i].iterations || 6883 (request->scan_plans[i].iterations > 6884 wiphy->max_sched_scan_plan_iterations)) 6885 return -EINVAL; 6886 } else if (i < n_plans - 1) { 6887 /* 6888 * All scan plans but the last one must specify 6889 * a finite number of iterations 6890 */ 6891 return -EINVAL; 6892 } 6893 6894 i++; 6895 } 6896 6897 /* 6898 * The last scan plan must not specify the number of 6899 * iterations, it is supposed to run infinitely 6900 */ 6901 if (request->scan_plans[n_plans - 1].iterations) 6902 return -EINVAL; 6903 6904 return 0; 6905 } 6906 6907 static struct cfg80211_sched_scan_request * 6908 nl80211_parse_sched_scan(struct wiphy *wiphy, struct wireless_dev *wdev, 6909 struct nlattr **attrs, int max_match_sets) 6910 { 6911 struct cfg80211_sched_scan_request *request; 6912 struct nlattr *attr; 6913 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i, n_plans = 0; 6914 enum nl80211_band band; 6915 size_t ie_len; 6916 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1]; 6917 s32 default_match_rssi = NL80211_SCAN_RSSI_THOLD_OFF; 6918 6919 if (!is_valid_ie_attr(attrs[NL80211_ATTR_IE])) 6920 return ERR_PTR(-EINVAL); 6921 6922 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) { 6923 n_channels = validate_scan_freqs( 6924 attrs[NL80211_ATTR_SCAN_FREQUENCIES]); 6925 if (!n_channels) 6926 return ERR_PTR(-EINVAL); 6927 } else { 6928 n_channels = ieee80211_get_num_supported_channels(wiphy); 6929 } 6930 6931 if (attrs[NL80211_ATTR_SCAN_SSIDS]) 6932 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS], 6933 tmp) 6934 n_ssids++; 6935 6936 if (n_ssids > wiphy->max_sched_scan_ssids) 6937 return ERR_PTR(-EINVAL); 6938 6939 /* 6940 * First, count the number of 'real' matchsets. Due to an issue with 6941 * the old implementation, matchsets containing only the RSSI attribute 6942 * (NL80211_SCHED_SCAN_MATCH_ATTR_RSSI) are considered as the 'default' 6943 * RSSI for all matchsets, rather than their own matchset for reporting 6944 * all APs with a strong RSSI. This is needed to be compatible with 6945 * older userspace that treated a matchset with only the RSSI as the 6946 * global RSSI for all other matchsets - if there are other matchsets. 6947 */ 6948 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) { 6949 nla_for_each_nested(attr, 6950 attrs[NL80211_ATTR_SCHED_SCAN_MATCH], 6951 tmp) { 6952 struct nlattr *rssi; 6953 6954 err = nla_parse_nested(tb, 6955 NL80211_SCHED_SCAN_MATCH_ATTR_MAX, 6956 attr, nl80211_match_policy); 6957 if (err) 6958 return ERR_PTR(err); 6959 /* add other standalone attributes here */ 6960 if (tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID]) { 6961 n_match_sets++; 6962 continue; 6963 } 6964 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI]; 6965 if (rssi) 6966 default_match_rssi = nla_get_s32(rssi); 6967 } 6968 } 6969 6970 /* However, if there's no other matchset, add the RSSI one */ 6971 if (!n_match_sets && default_match_rssi != NL80211_SCAN_RSSI_THOLD_OFF) 6972 n_match_sets = 1; 6973 6974 if (n_match_sets > max_match_sets) 6975 return ERR_PTR(-EINVAL); 6976 6977 if (attrs[NL80211_ATTR_IE]) 6978 ie_len = nla_len(attrs[NL80211_ATTR_IE]); 6979 else 6980 ie_len = 0; 6981 6982 if (ie_len > wiphy->max_sched_scan_ie_len) 6983 return ERR_PTR(-EINVAL); 6984 6985 if (attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) { 6986 /* 6987 * NL80211_ATTR_SCHED_SCAN_INTERVAL must not be specified since 6988 * each scan plan already specifies its own interval 6989 */ 6990 if (attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]) 6991 return ERR_PTR(-EINVAL); 6992 6993 nla_for_each_nested(attr, 6994 attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp) 6995 n_plans++; 6996 } else { 6997 /* 6998 * The scan interval attribute is kept for backward 6999 * compatibility. If no scan plans are specified and sched scan 7000 * interval is specified, one scan plan will be set with this 7001 * scan interval and infinite number of iterations. 7002 */ 7003 if (!attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]) 7004 return ERR_PTR(-EINVAL); 7005 7006 n_plans = 1; 7007 } 7008 7009 if (!n_plans || n_plans > wiphy->max_sched_scan_plans) 7010 return ERR_PTR(-EINVAL); 7011 7012 if (!wiphy_ext_feature_isset( 7013 wiphy, NL80211_EXT_FEATURE_SCHED_SCAN_RELATIVE_RSSI) && 7014 (attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI] || 7015 attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST])) 7016 return ERR_PTR(-EINVAL); 7017 7018 request = kzalloc(sizeof(*request) 7019 + sizeof(*request->ssids) * n_ssids 7020 + sizeof(*request->match_sets) * n_match_sets 7021 + sizeof(*request->scan_plans) * n_plans 7022 + sizeof(*request->channels) * n_channels 7023 + ie_len, GFP_KERNEL); 7024 if (!request) 7025 return ERR_PTR(-ENOMEM); 7026 7027 if (n_ssids) 7028 request->ssids = (void *)&request->channels[n_channels]; 7029 request->n_ssids = n_ssids; 7030 if (ie_len) { 7031 if (n_ssids) 7032 request->ie = (void *)(request->ssids + n_ssids); 7033 else 7034 request->ie = (void *)(request->channels + n_channels); 7035 } 7036 7037 if (n_match_sets) { 7038 if (request->ie) 7039 request->match_sets = (void *)(request->ie + ie_len); 7040 else if (n_ssids) 7041 request->match_sets = 7042 (void *)(request->ssids + n_ssids); 7043 else 7044 request->match_sets = 7045 (void *)(request->channels + n_channels); 7046 } 7047 request->n_match_sets = n_match_sets; 7048 7049 if (n_match_sets) 7050 request->scan_plans = (void *)(request->match_sets + 7051 n_match_sets); 7052 else if (request->ie) 7053 request->scan_plans = (void *)(request->ie + ie_len); 7054 else if (n_ssids) 7055 request->scan_plans = (void *)(request->ssids + n_ssids); 7056 else 7057 request->scan_plans = (void *)(request->channels + n_channels); 7058 7059 request->n_scan_plans = n_plans; 7060 7061 i = 0; 7062 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) { 7063 /* user specified, bail out if channel not found */ 7064 nla_for_each_nested(attr, 7065 attrs[NL80211_ATTR_SCAN_FREQUENCIES], 7066 tmp) { 7067 struct ieee80211_channel *chan; 7068 7069 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr)); 7070 7071 if (!chan) { 7072 err = -EINVAL; 7073 goto out_free; 7074 } 7075 7076 /* ignore disabled channels */ 7077 if (chan->flags & IEEE80211_CHAN_DISABLED) 7078 continue; 7079 7080 request->channels[i] = chan; 7081 i++; 7082 } 7083 } else { 7084 /* all channels */ 7085 for (band = 0; band < NUM_NL80211_BANDS; band++) { 7086 int j; 7087 7088 if (!wiphy->bands[band]) 7089 continue; 7090 for (j = 0; j < wiphy->bands[band]->n_channels; j++) { 7091 struct ieee80211_channel *chan; 7092 7093 chan = &wiphy->bands[band]->channels[j]; 7094 7095 if (chan->flags & IEEE80211_CHAN_DISABLED) 7096 continue; 7097 7098 request->channels[i] = chan; 7099 i++; 7100 } 7101 } 7102 } 7103 7104 if (!i) { 7105 err = -EINVAL; 7106 goto out_free; 7107 } 7108 7109 request->n_channels = i; 7110 7111 i = 0; 7112 if (n_ssids) { 7113 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS], 7114 tmp) { 7115 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) { 7116 err = -EINVAL; 7117 goto out_free; 7118 } 7119 request->ssids[i].ssid_len = nla_len(attr); 7120 memcpy(request->ssids[i].ssid, nla_data(attr), 7121 nla_len(attr)); 7122 i++; 7123 } 7124 } 7125 7126 i = 0; 7127 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) { 7128 nla_for_each_nested(attr, 7129 attrs[NL80211_ATTR_SCHED_SCAN_MATCH], 7130 tmp) { 7131 struct nlattr *ssid, *rssi; 7132 7133 err = nla_parse_nested(tb, 7134 NL80211_SCHED_SCAN_MATCH_ATTR_MAX, 7135 attr, nl80211_match_policy); 7136 if (err) 7137 goto out_free; 7138 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID]; 7139 if (ssid) { 7140 if (WARN_ON(i >= n_match_sets)) { 7141 /* this indicates a programming error, 7142 * the loop above should have verified 7143 * things properly 7144 */ 7145 err = -EINVAL; 7146 goto out_free; 7147 } 7148 7149 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) { 7150 err = -EINVAL; 7151 goto out_free; 7152 } 7153 memcpy(request->match_sets[i].ssid.ssid, 7154 nla_data(ssid), nla_len(ssid)); 7155 request->match_sets[i].ssid.ssid_len = 7156 nla_len(ssid); 7157 /* special attribute - old implementation w/a */ 7158 request->match_sets[i].rssi_thold = 7159 default_match_rssi; 7160 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI]; 7161 if (rssi) 7162 request->match_sets[i].rssi_thold = 7163 nla_get_s32(rssi); 7164 } 7165 i++; 7166 } 7167 7168 /* there was no other matchset, so the RSSI one is alone */ 7169 if (i == 0 && n_match_sets) 7170 request->match_sets[0].rssi_thold = default_match_rssi; 7171 7172 request->min_rssi_thold = INT_MAX; 7173 for (i = 0; i < n_match_sets; i++) 7174 request->min_rssi_thold = 7175 min(request->match_sets[i].rssi_thold, 7176 request->min_rssi_thold); 7177 } else { 7178 request->min_rssi_thold = NL80211_SCAN_RSSI_THOLD_OFF; 7179 } 7180 7181 if (ie_len) { 7182 request->ie_len = ie_len; 7183 memcpy((void *)request->ie, 7184 nla_data(attrs[NL80211_ATTR_IE]), 7185 request->ie_len); 7186 } 7187 7188 if (attrs[NL80211_ATTR_SCAN_FLAGS]) { 7189 request->flags = nla_get_u32( 7190 attrs[NL80211_ATTR_SCAN_FLAGS]); 7191 if ((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) && 7192 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) { 7193 err = -EOPNOTSUPP; 7194 goto out_free; 7195 } 7196 7197 if (request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) { 7198 u32 flg = NL80211_FEATURE_SCHED_SCAN_RANDOM_MAC_ADDR; 7199 7200 if (!wdev) /* must be net-detect */ 7201 flg = NL80211_FEATURE_ND_RANDOM_MAC_ADDR; 7202 7203 if (!(wiphy->features & flg)) { 7204 err = -EOPNOTSUPP; 7205 goto out_free; 7206 } 7207 7208 if (wdev && wdev->current_bss) { 7209 err = -EOPNOTSUPP; 7210 goto out_free; 7211 } 7212 7213 err = nl80211_parse_random_mac(attrs, request->mac_addr, 7214 request->mac_addr_mask); 7215 if (err) 7216 goto out_free; 7217 } 7218 } 7219 7220 if (attrs[NL80211_ATTR_SCHED_SCAN_DELAY]) 7221 request->delay = 7222 nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_DELAY]); 7223 7224 if (attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI]) { 7225 request->relative_rssi = nla_get_s8( 7226 attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI]); 7227 request->relative_rssi_set = true; 7228 } 7229 7230 if (request->relative_rssi_set && 7231 attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]) { 7232 struct nl80211_bss_select_rssi_adjust *rssi_adjust; 7233 7234 rssi_adjust = nla_data( 7235 attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]); 7236 request->rssi_adjust.band = rssi_adjust->band; 7237 request->rssi_adjust.delta = rssi_adjust->delta; 7238 if (!is_band_valid(wiphy, request->rssi_adjust.band)) { 7239 err = -EINVAL; 7240 goto out_free; 7241 } 7242 } 7243 7244 err = nl80211_parse_sched_scan_plans(wiphy, n_plans, request, attrs); 7245 if (err) 7246 goto out_free; 7247 7248 request->scan_start = jiffies; 7249 7250 return request; 7251 7252 out_free: 7253 kfree(request); 7254 return ERR_PTR(err); 7255 } 7256 7257 static int nl80211_start_sched_scan(struct sk_buff *skb, 7258 struct genl_info *info) 7259 { 7260 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7261 struct net_device *dev = info->user_ptr[1]; 7262 struct wireless_dev *wdev = dev->ieee80211_ptr; 7263 struct cfg80211_sched_scan_request *sched_scan_req; 7264 int err; 7265 7266 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) || 7267 !rdev->ops->sched_scan_start) 7268 return -EOPNOTSUPP; 7269 7270 if (rdev->sched_scan_req) 7271 return -EINPROGRESS; 7272 7273 sched_scan_req = nl80211_parse_sched_scan(&rdev->wiphy, wdev, 7274 info->attrs, 7275 rdev->wiphy.max_match_sets); 7276 7277 err = PTR_ERR_OR_ZERO(sched_scan_req); 7278 if (err) 7279 goto out_err; 7280 7281 err = rdev_sched_scan_start(rdev, dev, sched_scan_req); 7282 if (err) 7283 goto out_free; 7284 7285 sched_scan_req->dev = dev; 7286 sched_scan_req->wiphy = &rdev->wiphy; 7287 7288 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) 7289 sched_scan_req->owner_nlportid = info->snd_portid; 7290 7291 rcu_assign_pointer(rdev->sched_scan_req, sched_scan_req); 7292 7293 nl80211_send_sched_scan(rdev, dev, 7294 NL80211_CMD_START_SCHED_SCAN); 7295 return 0; 7296 7297 out_free: 7298 kfree(sched_scan_req); 7299 out_err: 7300 return err; 7301 } 7302 7303 static int nl80211_stop_sched_scan(struct sk_buff *skb, 7304 struct genl_info *info) 7305 { 7306 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7307 7308 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) || 7309 !rdev->ops->sched_scan_stop) 7310 return -EOPNOTSUPP; 7311 7312 return __cfg80211_stop_sched_scan(rdev, false); 7313 } 7314 7315 static int nl80211_start_radar_detection(struct sk_buff *skb, 7316 struct genl_info *info) 7317 { 7318 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7319 struct net_device *dev = info->user_ptr[1]; 7320 struct wireless_dev *wdev = dev->ieee80211_ptr; 7321 struct cfg80211_chan_def chandef; 7322 enum nl80211_dfs_regions dfs_region; 7323 unsigned int cac_time_ms; 7324 int err; 7325 7326 dfs_region = reg_get_dfs_region(wdev->wiphy); 7327 if (dfs_region == NL80211_DFS_UNSET) 7328 return -EINVAL; 7329 7330 err = nl80211_parse_chandef(rdev, info, &chandef); 7331 if (err) 7332 return err; 7333 7334 if (netif_carrier_ok(dev)) 7335 return -EBUSY; 7336 7337 if (wdev->cac_started) 7338 return -EBUSY; 7339 7340 err = cfg80211_chandef_dfs_required(wdev->wiphy, &chandef, 7341 wdev->iftype); 7342 if (err < 0) 7343 return err; 7344 7345 if (err == 0) 7346 return -EINVAL; 7347 7348 if (!cfg80211_chandef_dfs_usable(wdev->wiphy, &chandef)) 7349 return -EINVAL; 7350 7351 if (!rdev->ops->start_radar_detection) 7352 return -EOPNOTSUPP; 7353 7354 cac_time_ms = cfg80211_chandef_dfs_cac_time(&rdev->wiphy, &chandef); 7355 if (WARN_ON(!cac_time_ms)) 7356 cac_time_ms = IEEE80211_DFS_MIN_CAC_TIME_MS; 7357 7358 err = rdev_start_radar_detection(rdev, dev, &chandef, cac_time_ms); 7359 if (!err) { 7360 wdev->chandef = chandef; 7361 wdev->cac_started = true; 7362 wdev->cac_start_time = jiffies; 7363 wdev->cac_time_ms = cac_time_ms; 7364 } 7365 return err; 7366 } 7367 7368 static int nl80211_channel_switch(struct sk_buff *skb, struct genl_info *info) 7369 { 7370 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7371 struct net_device *dev = info->user_ptr[1]; 7372 struct wireless_dev *wdev = dev->ieee80211_ptr; 7373 struct cfg80211_csa_settings params; 7374 /* csa_attrs is defined static to avoid waste of stack size - this 7375 * function is called under RTNL lock, so this should not be a problem. 7376 */ 7377 static struct nlattr *csa_attrs[NL80211_ATTR_MAX+1]; 7378 int err; 7379 bool need_new_beacon = false; 7380 int len, i; 7381 u32 cs_count; 7382 7383 if (!rdev->ops->channel_switch || 7384 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH)) 7385 return -EOPNOTSUPP; 7386 7387 switch (dev->ieee80211_ptr->iftype) { 7388 case NL80211_IFTYPE_AP: 7389 case NL80211_IFTYPE_P2P_GO: 7390 need_new_beacon = true; 7391 7392 /* useless if AP is not running */ 7393 if (!wdev->beacon_interval) 7394 return -ENOTCONN; 7395 break; 7396 case NL80211_IFTYPE_ADHOC: 7397 if (!wdev->ssid_len) 7398 return -ENOTCONN; 7399 break; 7400 case NL80211_IFTYPE_MESH_POINT: 7401 if (!wdev->mesh_id_len) 7402 return -ENOTCONN; 7403 break; 7404 default: 7405 return -EOPNOTSUPP; 7406 } 7407 7408 memset(¶ms, 0, sizeof(params)); 7409 7410 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] || 7411 !info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]) 7412 return -EINVAL; 7413 7414 /* only important for AP, IBSS and mesh create IEs internally */ 7415 if (need_new_beacon && !info->attrs[NL80211_ATTR_CSA_IES]) 7416 return -EINVAL; 7417 7418 /* Even though the attribute is u32, the specification says 7419 * u8, so let's make sure we don't overflow. 7420 */ 7421 cs_count = nla_get_u32(info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]); 7422 if (cs_count > 255) 7423 return -EINVAL; 7424 7425 params.count = cs_count; 7426 7427 if (!need_new_beacon) 7428 goto skip_beacons; 7429 7430 err = nl80211_parse_beacon(info->attrs, ¶ms.beacon_after); 7431 if (err) 7432 return err; 7433 7434 err = nla_parse_nested(csa_attrs, NL80211_ATTR_MAX, 7435 info->attrs[NL80211_ATTR_CSA_IES], 7436 nl80211_policy); 7437 if (err) 7438 return err; 7439 7440 err = nl80211_parse_beacon(csa_attrs, ¶ms.beacon_csa); 7441 if (err) 7442 return err; 7443 7444 if (!csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]) 7445 return -EINVAL; 7446 7447 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]); 7448 if (!len || (len % sizeof(u16))) 7449 return -EINVAL; 7450 7451 params.n_counter_offsets_beacon = len / sizeof(u16); 7452 if (rdev->wiphy.max_num_csa_counters && 7453 (params.n_counter_offsets_beacon > 7454 rdev->wiphy.max_num_csa_counters)) 7455 return -EINVAL; 7456 7457 params.counter_offsets_beacon = 7458 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]); 7459 7460 /* sanity checks - counters should fit and be the same */ 7461 for (i = 0; i < params.n_counter_offsets_beacon; i++) { 7462 u16 offset = params.counter_offsets_beacon[i]; 7463 7464 if (offset >= params.beacon_csa.tail_len) 7465 return -EINVAL; 7466 7467 if (params.beacon_csa.tail[offset] != params.count) 7468 return -EINVAL; 7469 } 7470 7471 if (csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]) { 7472 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]); 7473 if (!len || (len % sizeof(u16))) 7474 return -EINVAL; 7475 7476 params.n_counter_offsets_presp = len / sizeof(u16); 7477 if (rdev->wiphy.max_num_csa_counters && 7478 (params.n_counter_offsets_presp > 7479 rdev->wiphy.max_num_csa_counters)) 7480 return -EINVAL; 7481 7482 params.counter_offsets_presp = 7483 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]); 7484 7485 /* sanity checks - counters should fit and be the same */ 7486 for (i = 0; i < params.n_counter_offsets_presp; i++) { 7487 u16 offset = params.counter_offsets_presp[i]; 7488 7489 if (offset >= params.beacon_csa.probe_resp_len) 7490 return -EINVAL; 7491 7492 if (params.beacon_csa.probe_resp[offset] != 7493 params.count) 7494 return -EINVAL; 7495 } 7496 } 7497 7498 skip_beacons: 7499 err = nl80211_parse_chandef(rdev, info, ¶ms.chandef); 7500 if (err) 7501 return err; 7502 7503 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, ¶ms.chandef, 7504 wdev->iftype)) 7505 return -EINVAL; 7506 7507 err = cfg80211_chandef_dfs_required(wdev->wiphy, 7508 ¶ms.chandef, 7509 wdev->iftype); 7510 if (err < 0) 7511 return err; 7512 7513 if (err > 0) 7514 params.radar_required = true; 7515 7516 if (info->attrs[NL80211_ATTR_CH_SWITCH_BLOCK_TX]) 7517 params.block_tx = true; 7518 7519 wdev_lock(wdev); 7520 err = rdev_channel_switch(rdev, dev, ¶ms); 7521 wdev_unlock(wdev); 7522 7523 return err; 7524 } 7525 7526 static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb, 7527 u32 seq, int flags, 7528 struct cfg80211_registered_device *rdev, 7529 struct wireless_dev *wdev, 7530 struct cfg80211_internal_bss *intbss) 7531 { 7532 struct cfg80211_bss *res = &intbss->pub; 7533 const struct cfg80211_bss_ies *ies; 7534 void *hdr; 7535 struct nlattr *bss; 7536 7537 ASSERT_WDEV_LOCK(wdev); 7538 7539 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags, 7540 NL80211_CMD_NEW_SCAN_RESULTS); 7541 if (!hdr) 7542 return -1; 7543 7544 genl_dump_check_consistent(cb, hdr, &nl80211_fam); 7545 7546 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation)) 7547 goto nla_put_failure; 7548 if (wdev->netdev && 7549 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex)) 7550 goto nla_put_failure; 7551 if (nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 7552 NL80211_ATTR_PAD)) 7553 goto nla_put_failure; 7554 7555 bss = nla_nest_start(msg, NL80211_ATTR_BSS); 7556 if (!bss) 7557 goto nla_put_failure; 7558 if ((!is_zero_ether_addr(res->bssid) && 7559 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid))) 7560 goto nla_put_failure; 7561 7562 rcu_read_lock(); 7563 /* indicate whether we have probe response data or not */ 7564 if (rcu_access_pointer(res->proberesp_ies) && 7565 nla_put_flag(msg, NL80211_BSS_PRESP_DATA)) 7566 goto fail_unlock_rcu; 7567 7568 /* this pointer prefers to be pointed to probe response data 7569 * but is always valid 7570 */ 7571 ies = rcu_dereference(res->ies); 7572 if (ies) { 7573 if (nla_put_u64_64bit(msg, NL80211_BSS_TSF, ies->tsf, 7574 NL80211_BSS_PAD)) 7575 goto fail_unlock_rcu; 7576 if (ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS, 7577 ies->len, ies->data)) 7578 goto fail_unlock_rcu; 7579 } 7580 7581 /* and this pointer is always (unless driver didn't know) beacon data */ 7582 ies = rcu_dereference(res->beacon_ies); 7583 if (ies && ies->from_beacon) { 7584 if (nla_put_u64_64bit(msg, NL80211_BSS_BEACON_TSF, ies->tsf, 7585 NL80211_BSS_PAD)) 7586 goto fail_unlock_rcu; 7587 if (ies->len && nla_put(msg, NL80211_BSS_BEACON_IES, 7588 ies->len, ies->data)) 7589 goto fail_unlock_rcu; 7590 } 7591 rcu_read_unlock(); 7592 7593 if (res->beacon_interval && 7594 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval)) 7595 goto nla_put_failure; 7596 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) || 7597 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) || 7598 nla_put_u32(msg, NL80211_BSS_CHAN_WIDTH, res->scan_width) || 7599 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO, 7600 jiffies_to_msecs(jiffies - intbss->ts))) 7601 goto nla_put_failure; 7602 7603 if (intbss->parent_tsf && 7604 (nla_put_u64_64bit(msg, NL80211_BSS_PARENT_TSF, 7605 intbss->parent_tsf, NL80211_BSS_PAD) || 7606 nla_put(msg, NL80211_BSS_PARENT_BSSID, ETH_ALEN, 7607 intbss->parent_bssid))) 7608 goto nla_put_failure; 7609 7610 if (intbss->ts_boottime && 7611 nla_put_u64_64bit(msg, NL80211_BSS_LAST_SEEN_BOOTTIME, 7612 intbss->ts_boottime, NL80211_BSS_PAD)) 7613 goto nla_put_failure; 7614 7615 switch (rdev->wiphy.signal_type) { 7616 case CFG80211_SIGNAL_TYPE_MBM: 7617 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal)) 7618 goto nla_put_failure; 7619 break; 7620 case CFG80211_SIGNAL_TYPE_UNSPEC: 7621 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal)) 7622 goto nla_put_failure; 7623 break; 7624 default: 7625 break; 7626 } 7627 7628 switch (wdev->iftype) { 7629 case NL80211_IFTYPE_P2P_CLIENT: 7630 case NL80211_IFTYPE_STATION: 7631 if (intbss == wdev->current_bss && 7632 nla_put_u32(msg, NL80211_BSS_STATUS, 7633 NL80211_BSS_STATUS_ASSOCIATED)) 7634 goto nla_put_failure; 7635 break; 7636 case NL80211_IFTYPE_ADHOC: 7637 if (intbss == wdev->current_bss && 7638 nla_put_u32(msg, NL80211_BSS_STATUS, 7639 NL80211_BSS_STATUS_IBSS_JOINED)) 7640 goto nla_put_failure; 7641 break; 7642 default: 7643 break; 7644 } 7645 7646 nla_nest_end(msg, bss); 7647 7648 genlmsg_end(msg, hdr); 7649 return 0; 7650 7651 fail_unlock_rcu: 7652 rcu_read_unlock(); 7653 nla_put_failure: 7654 genlmsg_cancel(msg, hdr); 7655 return -EMSGSIZE; 7656 } 7657 7658 static int nl80211_dump_scan(struct sk_buff *skb, struct netlink_callback *cb) 7659 { 7660 struct cfg80211_registered_device *rdev; 7661 struct cfg80211_internal_bss *scan; 7662 struct wireless_dev *wdev; 7663 int start = cb->args[2], idx = 0; 7664 int err; 7665 7666 rtnl_lock(); 7667 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 7668 if (err) { 7669 rtnl_unlock(); 7670 return err; 7671 } 7672 7673 wdev_lock(wdev); 7674 spin_lock_bh(&rdev->bss_lock); 7675 cfg80211_bss_expire(rdev); 7676 7677 cb->seq = rdev->bss_generation; 7678 7679 list_for_each_entry(scan, &rdev->bss_list, list) { 7680 if (++idx <= start) 7681 continue; 7682 if (nl80211_send_bss(skb, cb, 7683 cb->nlh->nlmsg_seq, NLM_F_MULTI, 7684 rdev, wdev, scan) < 0) { 7685 idx--; 7686 break; 7687 } 7688 } 7689 7690 spin_unlock_bh(&rdev->bss_lock); 7691 wdev_unlock(wdev); 7692 7693 cb->args[2] = idx; 7694 rtnl_unlock(); 7695 7696 return skb->len; 7697 } 7698 7699 static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq, 7700 int flags, struct net_device *dev, 7701 bool allow_radio_stats, 7702 struct survey_info *survey) 7703 { 7704 void *hdr; 7705 struct nlattr *infoattr; 7706 7707 /* skip radio stats if userspace didn't request them */ 7708 if (!survey->channel && !allow_radio_stats) 7709 return 0; 7710 7711 hdr = nl80211hdr_put(msg, portid, seq, flags, 7712 NL80211_CMD_NEW_SURVEY_RESULTS); 7713 if (!hdr) 7714 return -ENOMEM; 7715 7716 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex)) 7717 goto nla_put_failure; 7718 7719 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO); 7720 if (!infoattr) 7721 goto nla_put_failure; 7722 7723 if (survey->channel && 7724 nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY, 7725 survey->channel->center_freq)) 7726 goto nla_put_failure; 7727 7728 if ((survey->filled & SURVEY_INFO_NOISE_DBM) && 7729 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise)) 7730 goto nla_put_failure; 7731 if ((survey->filled & SURVEY_INFO_IN_USE) && 7732 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE)) 7733 goto nla_put_failure; 7734 if ((survey->filled & SURVEY_INFO_TIME) && 7735 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME, 7736 survey->time, NL80211_SURVEY_INFO_PAD)) 7737 goto nla_put_failure; 7738 if ((survey->filled & SURVEY_INFO_TIME_BUSY) && 7739 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_BUSY, 7740 survey->time_busy, NL80211_SURVEY_INFO_PAD)) 7741 goto nla_put_failure; 7742 if ((survey->filled & SURVEY_INFO_TIME_EXT_BUSY) && 7743 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_EXT_BUSY, 7744 survey->time_ext_busy, NL80211_SURVEY_INFO_PAD)) 7745 goto nla_put_failure; 7746 if ((survey->filled & SURVEY_INFO_TIME_RX) && 7747 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_RX, 7748 survey->time_rx, NL80211_SURVEY_INFO_PAD)) 7749 goto nla_put_failure; 7750 if ((survey->filled & SURVEY_INFO_TIME_TX) && 7751 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_TX, 7752 survey->time_tx, NL80211_SURVEY_INFO_PAD)) 7753 goto nla_put_failure; 7754 if ((survey->filled & SURVEY_INFO_TIME_SCAN) && 7755 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_SCAN, 7756 survey->time_scan, NL80211_SURVEY_INFO_PAD)) 7757 goto nla_put_failure; 7758 7759 nla_nest_end(msg, infoattr); 7760 7761 genlmsg_end(msg, hdr); 7762 return 0; 7763 7764 nla_put_failure: 7765 genlmsg_cancel(msg, hdr); 7766 return -EMSGSIZE; 7767 } 7768 7769 static int nl80211_dump_survey(struct sk_buff *skb, struct netlink_callback *cb) 7770 { 7771 struct nlattr **attrbuf = genl_family_attrbuf(&nl80211_fam); 7772 struct survey_info survey; 7773 struct cfg80211_registered_device *rdev; 7774 struct wireless_dev *wdev; 7775 int survey_idx = cb->args[2]; 7776 int res; 7777 bool radio_stats; 7778 7779 rtnl_lock(); 7780 res = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 7781 if (res) 7782 goto out_err; 7783 7784 /* prepare_wdev_dump parsed the attributes */ 7785 radio_stats = attrbuf[NL80211_ATTR_SURVEY_RADIO_STATS]; 7786 7787 if (!wdev->netdev) { 7788 res = -EINVAL; 7789 goto out_err; 7790 } 7791 7792 if (!rdev->ops->dump_survey) { 7793 res = -EOPNOTSUPP; 7794 goto out_err; 7795 } 7796 7797 while (1) { 7798 res = rdev_dump_survey(rdev, wdev->netdev, survey_idx, &survey); 7799 if (res == -ENOENT) 7800 break; 7801 if (res) 7802 goto out_err; 7803 7804 /* don't send disabled channels, but do send non-channel data */ 7805 if (survey.channel && 7806 survey.channel->flags & IEEE80211_CHAN_DISABLED) { 7807 survey_idx++; 7808 continue; 7809 } 7810 7811 if (nl80211_send_survey(skb, 7812 NETLINK_CB(cb->skb).portid, 7813 cb->nlh->nlmsg_seq, NLM_F_MULTI, 7814 wdev->netdev, radio_stats, &survey) < 0) 7815 goto out; 7816 survey_idx++; 7817 } 7818 7819 out: 7820 cb->args[2] = survey_idx; 7821 res = skb->len; 7822 out_err: 7823 rtnl_unlock(); 7824 return res; 7825 } 7826 7827 static bool nl80211_valid_wpa_versions(u32 wpa_versions) 7828 { 7829 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 | 7830 NL80211_WPA_VERSION_2)); 7831 } 7832 7833 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info) 7834 { 7835 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7836 struct net_device *dev = info->user_ptr[1]; 7837 struct ieee80211_channel *chan; 7838 const u8 *bssid, *ssid, *ie = NULL, *auth_data = NULL; 7839 int err, ssid_len, ie_len = 0, auth_data_len = 0; 7840 enum nl80211_auth_type auth_type; 7841 struct key_parse key; 7842 bool local_state_change; 7843 7844 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 7845 return -EINVAL; 7846 7847 if (!info->attrs[NL80211_ATTR_MAC]) 7848 return -EINVAL; 7849 7850 if (!info->attrs[NL80211_ATTR_AUTH_TYPE]) 7851 return -EINVAL; 7852 7853 if (!info->attrs[NL80211_ATTR_SSID]) 7854 return -EINVAL; 7855 7856 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ]) 7857 return -EINVAL; 7858 7859 err = nl80211_parse_key(info, &key); 7860 if (err) 7861 return err; 7862 7863 if (key.idx >= 0) { 7864 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP) 7865 return -EINVAL; 7866 if (!key.p.key || !key.p.key_len) 7867 return -EINVAL; 7868 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 || 7869 key.p.key_len != WLAN_KEY_LEN_WEP40) && 7870 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 || 7871 key.p.key_len != WLAN_KEY_LEN_WEP104)) 7872 return -EINVAL; 7873 if (key.idx > 3) 7874 return -EINVAL; 7875 } else { 7876 key.p.key_len = 0; 7877 key.p.key = NULL; 7878 } 7879 7880 if (key.idx >= 0) { 7881 int i; 7882 bool ok = false; 7883 7884 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) { 7885 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) { 7886 ok = true; 7887 break; 7888 } 7889 } 7890 if (!ok) 7891 return -EINVAL; 7892 } 7893 7894 if (!rdev->ops->auth) 7895 return -EOPNOTSUPP; 7896 7897 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 7898 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 7899 return -EOPNOTSUPP; 7900 7901 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 7902 chan = nl80211_get_valid_chan(&rdev->wiphy, 7903 info->attrs[NL80211_ATTR_WIPHY_FREQ]); 7904 if (!chan) 7905 return -EINVAL; 7906 7907 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 7908 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]); 7909 7910 if (info->attrs[NL80211_ATTR_IE]) { 7911 ie = nla_data(info->attrs[NL80211_ATTR_IE]); 7912 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 7913 } 7914 7915 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]); 7916 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE)) 7917 return -EINVAL; 7918 7919 if ((auth_type == NL80211_AUTHTYPE_SAE || 7920 auth_type == NL80211_AUTHTYPE_FILS_SK || 7921 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS || 7922 auth_type == NL80211_AUTHTYPE_FILS_PK) && 7923 !info->attrs[NL80211_ATTR_AUTH_DATA]) 7924 return -EINVAL; 7925 7926 if (info->attrs[NL80211_ATTR_AUTH_DATA]) { 7927 if (auth_type != NL80211_AUTHTYPE_SAE && 7928 auth_type != NL80211_AUTHTYPE_FILS_SK && 7929 auth_type != NL80211_AUTHTYPE_FILS_SK_PFS && 7930 auth_type != NL80211_AUTHTYPE_FILS_PK) 7931 return -EINVAL; 7932 auth_data = nla_data(info->attrs[NL80211_ATTR_AUTH_DATA]); 7933 auth_data_len = nla_len(info->attrs[NL80211_ATTR_AUTH_DATA]); 7934 /* need to include at least Auth Transaction and Status Code */ 7935 if (auth_data_len < 4) 7936 return -EINVAL; 7937 } 7938 7939 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE]; 7940 7941 /* 7942 * Since we no longer track auth state, ignore 7943 * requests to only change local state. 7944 */ 7945 if (local_state_change) 7946 return 0; 7947 7948 wdev_lock(dev->ieee80211_ptr); 7949 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid, 7950 ssid, ssid_len, ie, ie_len, 7951 key.p.key, key.p.key_len, key.idx, 7952 auth_data, auth_data_len); 7953 wdev_unlock(dev->ieee80211_ptr); 7954 return err; 7955 } 7956 7957 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev, 7958 struct genl_info *info, 7959 struct cfg80211_crypto_settings *settings, 7960 int cipher_limit) 7961 { 7962 memset(settings, 0, sizeof(*settings)); 7963 7964 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT]; 7965 7966 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) { 7967 u16 proto; 7968 7969 proto = nla_get_u16( 7970 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]); 7971 settings->control_port_ethertype = cpu_to_be16(proto); 7972 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) && 7973 proto != ETH_P_PAE) 7974 return -EINVAL; 7975 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT]) 7976 settings->control_port_no_encrypt = true; 7977 } else 7978 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE); 7979 7980 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) { 7981 void *data; 7982 int len, i; 7983 7984 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]); 7985 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]); 7986 settings->n_ciphers_pairwise = len / sizeof(u32); 7987 7988 if (len % sizeof(u32)) 7989 return -EINVAL; 7990 7991 if (settings->n_ciphers_pairwise > cipher_limit) 7992 return -EINVAL; 7993 7994 memcpy(settings->ciphers_pairwise, data, len); 7995 7996 for (i = 0; i < settings->n_ciphers_pairwise; i++) 7997 if (!cfg80211_supported_cipher_suite( 7998 &rdev->wiphy, 7999 settings->ciphers_pairwise[i])) 8000 return -EINVAL; 8001 } 8002 8003 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) { 8004 settings->cipher_group = 8005 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]); 8006 if (!cfg80211_supported_cipher_suite(&rdev->wiphy, 8007 settings->cipher_group)) 8008 return -EINVAL; 8009 } 8010 8011 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) { 8012 settings->wpa_versions = 8013 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]); 8014 if (!nl80211_valid_wpa_versions(settings->wpa_versions)) 8015 return -EINVAL; 8016 } 8017 8018 if (info->attrs[NL80211_ATTR_AKM_SUITES]) { 8019 void *data; 8020 int len; 8021 8022 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]); 8023 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]); 8024 settings->n_akm_suites = len / sizeof(u32); 8025 8026 if (len % sizeof(u32)) 8027 return -EINVAL; 8028 8029 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES) 8030 return -EINVAL; 8031 8032 memcpy(settings->akm_suites, data, len); 8033 } 8034 8035 return 0; 8036 } 8037 8038 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info) 8039 { 8040 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8041 struct net_device *dev = info->user_ptr[1]; 8042 struct ieee80211_channel *chan; 8043 struct cfg80211_assoc_request req = {}; 8044 const u8 *bssid, *ssid; 8045 int err, ssid_len = 0; 8046 8047 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8048 return -EINVAL; 8049 8050 if (!info->attrs[NL80211_ATTR_MAC] || 8051 !info->attrs[NL80211_ATTR_SSID] || 8052 !info->attrs[NL80211_ATTR_WIPHY_FREQ]) 8053 return -EINVAL; 8054 8055 if (!rdev->ops->assoc) 8056 return -EOPNOTSUPP; 8057 8058 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8059 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8060 return -EOPNOTSUPP; 8061 8062 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8063 8064 chan = nl80211_get_valid_chan(&rdev->wiphy, 8065 info->attrs[NL80211_ATTR_WIPHY_FREQ]); 8066 if (!chan) 8067 return -EINVAL; 8068 8069 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 8070 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]); 8071 8072 if (info->attrs[NL80211_ATTR_IE]) { 8073 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8074 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8075 } 8076 8077 if (info->attrs[NL80211_ATTR_USE_MFP]) { 8078 enum nl80211_mfp mfp = 8079 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]); 8080 if (mfp == NL80211_MFP_REQUIRED) 8081 req.use_mfp = true; 8082 else if (mfp != NL80211_MFP_NO) 8083 return -EINVAL; 8084 } 8085 8086 if (info->attrs[NL80211_ATTR_PREV_BSSID]) 8087 req.prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]); 8088 8089 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT])) 8090 req.flags |= ASSOC_REQ_DISABLE_HT; 8091 8092 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8093 memcpy(&req.ht_capa_mask, 8094 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]), 8095 sizeof(req.ht_capa_mask)); 8096 8097 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) { 8098 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8099 return -EINVAL; 8100 memcpy(&req.ht_capa, 8101 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]), 8102 sizeof(req.ht_capa)); 8103 } 8104 8105 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT])) 8106 req.flags |= ASSOC_REQ_DISABLE_VHT; 8107 8108 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) 8109 memcpy(&req.vht_capa_mask, 8110 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]), 8111 sizeof(req.vht_capa_mask)); 8112 8113 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) { 8114 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) 8115 return -EINVAL; 8116 memcpy(&req.vht_capa, 8117 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]), 8118 sizeof(req.vht_capa)); 8119 } 8120 8121 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) { 8122 if (!((rdev->wiphy.features & 8123 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) && 8124 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) && 8125 !wiphy_ext_feature_isset(&rdev->wiphy, 8126 NL80211_EXT_FEATURE_RRM)) 8127 return -EINVAL; 8128 req.flags |= ASSOC_REQ_USE_RRM; 8129 } 8130 8131 if (info->attrs[NL80211_ATTR_FILS_KEK]) { 8132 req.fils_kek = nla_data(info->attrs[NL80211_ATTR_FILS_KEK]); 8133 req.fils_kek_len = nla_len(info->attrs[NL80211_ATTR_FILS_KEK]); 8134 if (!info->attrs[NL80211_ATTR_FILS_NONCES]) 8135 return -EINVAL; 8136 req.fils_nonces = 8137 nla_data(info->attrs[NL80211_ATTR_FILS_NONCES]); 8138 } 8139 8140 err = nl80211_crypto_settings(rdev, info, &req.crypto, 1); 8141 if (!err) { 8142 wdev_lock(dev->ieee80211_ptr); 8143 8144 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, 8145 ssid, ssid_len, &req); 8146 8147 if (!err && info->attrs[NL80211_ATTR_SOCKET_OWNER]) { 8148 dev->ieee80211_ptr->conn_owner_nlportid = 8149 info->snd_portid; 8150 memcpy(dev->ieee80211_ptr->disconnect_bssid, 8151 bssid, ETH_ALEN); 8152 } 8153 8154 wdev_unlock(dev->ieee80211_ptr); 8155 } 8156 8157 return err; 8158 } 8159 8160 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info) 8161 { 8162 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8163 struct net_device *dev = info->user_ptr[1]; 8164 const u8 *ie = NULL, *bssid; 8165 int ie_len = 0, err; 8166 u16 reason_code; 8167 bool local_state_change; 8168 8169 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8170 return -EINVAL; 8171 8172 if (!info->attrs[NL80211_ATTR_MAC]) 8173 return -EINVAL; 8174 8175 if (!info->attrs[NL80211_ATTR_REASON_CODE]) 8176 return -EINVAL; 8177 8178 if (!rdev->ops->deauth) 8179 return -EOPNOTSUPP; 8180 8181 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8182 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8183 return -EOPNOTSUPP; 8184 8185 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8186 8187 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]); 8188 if (reason_code == 0) { 8189 /* Reason Code 0 is reserved */ 8190 return -EINVAL; 8191 } 8192 8193 if (info->attrs[NL80211_ATTR_IE]) { 8194 ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8195 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8196 } 8197 8198 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE]; 8199 8200 wdev_lock(dev->ieee80211_ptr); 8201 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code, 8202 local_state_change); 8203 wdev_unlock(dev->ieee80211_ptr); 8204 return err; 8205 } 8206 8207 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info) 8208 { 8209 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8210 struct net_device *dev = info->user_ptr[1]; 8211 const u8 *ie = NULL, *bssid; 8212 int ie_len = 0, err; 8213 u16 reason_code; 8214 bool local_state_change; 8215 8216 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8217 return -EINVAL; 8218 8219 if (!info->attrs[NL80211_ATTR_MAC]) 8220 return -EINVAL; 8221 8222 if (!info->attrs[NL80211_ATTR_REASON_CODE]) 8223 return -EINVAL; 8224 8225 if (!rdev->ops->disassoc) 8226 return -EOPNOTSUPP; 8227 8228 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8229 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8230 return -EOPNOTSUPP; 8231 8232 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8233 8234 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]); 8235 if (reason_code == 0) { 8236 /* Reason Code 0 is reserved */ 8237 return -EINVAL; 8238 } 8239 8240 if (info->attrs[NL80211_ATTR_IE]) { 8241 ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8242 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8243 } 8244 8245 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE]; 8246 8247 wdev_lock(dev->ieee80211_ptr); 8248 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code, 8249 local_state_change); 8250 wdev_unlock(dev->ieee80211_ptr); 8251 return err; 8252 } 8253 8254 static bool 8255 nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev, 8256 int mcast_rate[NUM_NL80211_BANDS], 8257 int rateval) 8258 { 8259 struct wiphy *wiphy = &rdev->wiphy; 8260 bool found = false; 8261 int band, i; 8262 8263 for (band = 0; band < NUM_NL80211_BANDS; band++) { 8264 struct ieee80211_supported_band *sband; 8265 8266 sband = wiphy->bands[band]; 8267 if (!sband) 8268 continue; 8269 8270 for (i = 0; i < sband->n_bitrates; i++) { 8271 if (sband->bitrates[i].bitrate == rateval) { 8272 mcast_rate[band] = i + 1; 8273 found = true; 8274 break; 8275 } 8276 } 8277 } 8278 8279 return found; 8280 } 8281 8282 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info) 8283 { 8284 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8285 struct net_device *dev = info->user_ptr[1]; 8286 struct cfg80211_ibss_params ibss; 8287 struct wiphy *wiphy; 8288 struct cfg80211_cached_keys *connkeys = NULL; 8289 int err; 8290 8291 memset(&ibss, 0, sizeof(ibss)); 8292 8293 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8294 return -EINVAL; 8295 8296 if (!info->attrs[NL80211_ATTR_SSID] || 8297 !nla_len(info->attrs[NL80211_ATTR_SSID])) 8298 return -EINVAL; 8299 8300 ibss.beacon_interval = 100; 8301 8302 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) 8303 ibss.beacon_interval = 8304 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]); 8305 8306 err = cfg80211_validate_beacon_int(rdev, NL80211_IFTYPE_ADHOC, 8307 ibss.beacon_interval); 8308 if (err) 8309 return err; 8310 8311 if (!rdev->ops->join_ibss) 8312 return -EOPNOTSUPP; 8313 8314 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) 8315 return -EOPNOTSUPP; 8316 8317 wiphy = &rdev->wiphy; 8318 8319 if (info->attrs[NL80211_ATTR_MAC]) { 8320 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8321 8322 if (!is_valid_ether_addr(ibss.bssid)) 8323 return -EINVAL; 8324 } 8325 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 8326 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]); 8327 8328 if (info->attrs[NL80211_ATTR_IE]) { 8329 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8330 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8331 } 8332 8333 err = nl80211_parse_chandef(rdev, info, &ibss.chandef); 8334 if (err) 8335 return err; 8336 8337 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef, 8338 NL80211_IFTYPE_ADHOC)) 8339 return -EINVAL; 8340 8341 switch (ibss.chandef.width) { 8342 case NL80211_CHAN_WIDTH_5: 8343 case NL80211_CHAN_WIDTH_10: 8344 case NL80211_CHAN_WIDTH_20_NOHT: 8345 break; 8346 case NL80211_CHAN_WIDTH_20: 8347 case NL80211_CHAN_WIDTH_40: 8348 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS)) 8349 return -EINVAL; 8350 break; 8351 case NL80211_CHAN_WIDTH_80: 8352 case NL80211_CHAN_WIDTH_80P80: 8353 case NL80211_CHAN_WIDTH_160: 8354 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS)) 8355 return -EINVAL; 8356 if (!wiphy_ext_feature_isset(&rdev->wiphy, 8357 NL80211_EXT_FEATURE_VHT_IBSS)) 8358 return -EINVAL; 8359 break; 8360 default: 8361 return -EINVAL; 8362 } 8363 8364 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED]; 8365 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY]; 8366 8367 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) { 8368 u8 *rates = 8369 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 8370 int n_rates = 8371 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 8372 struct ieee80211_supported_band *sband = 8373 wiphy->bands[ibss.chandef.chan->band]; 8374 8375 err = ieee80211_get_ratemask(sband, rates, n_rates, 8376 &ibss.basic_rates); 8377 if (err) 8378 return err; 8379 } 8380 8381 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8382 memcpy(&ibss.ht_capa_mask, 8383 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]), 8384 sizeof(ibss.ht_capa_mask)); 8385 8386 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) { 8387 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8388 return -EINVAL; 8389 memcpy(&ibss.ht_capa, 8390 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]), 8391 sizeof(ibss.ht_capa)); 8392 } 8393 8394 if (info->attrs[NL80211_ATTR_MCAST_RATE] && 8395 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate, 8396 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]))) 8397 return -EINVAL; 8398 8399 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) { 8400 bool no_ht = false; 8401 8402 connkeys = nl80211_parse_connkeys(rdev, 8403 info->attrs[NL80211_ATTR_KEYS], 8404 &no_ht); 8405 if (IS_ERR(connkeys)) 8406 return PTR_ERR(connkeys); 8407 8408 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) && 8409 no_ht) { 8410 kzfree(connkeys); 8411 return -EINVAL; 8412 } 8413 } 8414 8415 ibss.control_port = 8416 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]); 8417 8418 ibss.userspace_handles_dfs = 8419 nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]); 8420 8421 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys); 8422 if (err) 8423 kzfree(connkeys); 8424 return err; 8425 } 8426 8427 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info) 8428 { 8429 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8430 struct net_device *dev = info->user_ptr[1]; 8431 8432 if (!rdev->ops->leave_ibss) 8433 return -EOPNOTSUPP; 8434 8435 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) 8436 return -EOPNOTSUPP; 8437 8438 return cfg80211_leave_ibss(rdev, dev, false); 8439 } 8440 8441 static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info) 8442 { 8443 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8444 struct net_device *dev = info->user_ptr[1]; 8445 int mcast_rate[NUM_NL80211_BANDS]; 8446 u32 nla_rate; 8447 int err; 8448 8449 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC && 8450 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT && 8451 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_OCB) 8452 return -EOPNOTSUPP; 8453 8454 if (!rdev->ops->set_mcast_rate) 8455 return -EOPNOTSUPP; 8456 8457 memset(mcast_rate, 0, sizeof(mcast_rate)); 8458 8459 if (!info->attrs[NL80211_ATTR_MCAST_RATE]) 8460 return -EINVAL; 8461 8462 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]); 8463 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate)) 8464 return -EINVAL; 8465 8466 err = rdev_set_mcast_rate(rdev, dev, mcast_rate); 8467 8468 return err; 8469 } 8470 8471 static struct sk_buff * 8472 __cfg80211_alloc_vendor_skb(struct cfg80211_registered_device *rdev, 8473 struct wireless_dev *wdev, int approxlen, 8474 u32 portid, u32 seq, enum nl80211_commands cmd, 8475 enum nl80211_attrs attr, 8476 const struct nl80211_vendor_cmd_info *info, 8477 gfp_t gfp) 8478 { 8479 struct sk_buff *skb; 8480 void *hdr; 8481 struct nlattr *data; 8482 8483 skb = nlmsg_new(approxlen + 100, gfp); 8484 if (!skb) 8485 return NULL; 8486 8487 hdr = nl80211hdr_put(skb, portid, seq, 0, cmd); 8488 if (!hdr) { 8489 kfree_skb(skb); 8490 return NULL; 8491 } 8492 8493 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx)) 8494 goto nla_put_failure; 8495 8496 if (info) { 8497 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_ID, 8498 info->vendor_id)) 8499 goto nla_put_failure; 8500 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_SUBCMD, 8501 info->subcmd)) 8502 goto nla_put_failure; 8503 } 8504 8505 if (wdev) { 8506 if (nla_put_u64_64bit(skb, NL80211_ATTR_WDEV, 8507 wdev_id(wdev), NL80211_ATTR_PAD)) 8508 goto nla_put_failure; 8509 if (wdev->netdev && 8510 nla_put_u32(skb, NL80211_ATTR_IFINDEX, 8511 wdev->netdev->ifindex)) 8512 goto nla_put_failure; 8513 } 8514 8515 data = nla_nest_start(skb, attr); 8516 if (!data) 8517 goto nla_put_failure; 8518 8519 ((void **)skb->cb)[0] = rdev; 8520 ((void **)skb->cb)[1] = hdr; 8521 ((void **)skb->cb)[2] = data; 8522 8523 return skb; 8524 8525 nla_put_failure: 8526 kfree_skb(skb); 8527 return NULL; 8528 } 8529 8530 struct sk_buff *__cfg80211_alloc_event_skb(struct wiphy *wiphy, 8531 struct wireless_dev *wdev, 8532 enum nl80211_commands cmd, 8533 enum nl80211_attrs attr, 8534 int vendor_event_idx, 8535 int approxlen, gfp_t gfp) 8536 { 8537 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 8538 const struct nl80211_vendor_cmd_info *info; 8539 8540 switch (cmd) { 8541 case NL80211_CMD_TESTMODE: 8542 if (WARN_ON(vendor_event_idx != -1)) 8543 return NULL; 8544 info = NULL; 8545 break; 8546 case NL80211_CMD_VENDOR: 8547 if (WARN_ON(vendor_event_idx < 0 || 8548 vendor_event_idx >= wiphy->n_vendor_events)) 8549 return NULL; 8550 info = &wiphy->vendor_events[vendor_event_idx]; 8551 break; 8552 default: 8553 WARN_ON(1); 8554 return NULL; 8555 } 8556 8557 return __cfg80211_alloc_vendor_skb(rdev, wdev, approxlen, 0, 0, 8558 cmd, attr, info, gfp); 8559 } 8560 EXPORT_SYMBOL(__cfg80211_alloc_event_skb); 8561 8562 void __cfg80211_send_event_skb(struct sk_buff *skb, gfp_t gfp) 8563 { 8564 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0]; 8565 void *hdr = ((void **)skb->cb)[1]; 8566 struct nlattr *data = ((void **)skb->cb)[2]; 8567 enum nl80211_multicast_groups mcgrp = NL80211_MCGRP_TESTMODE; 8568 8569 /* clear CB data for netlink core to own from now on */ 8570 memset(skb->cb, 0, sizeof(skb->cb)); 8571 8572 nla_nest_end(skb, data); 8573 genlmsg_end(skb, hdr); 8574 8575 if (data->nla_type == NL80211_ATTR_VENDOR_DATA) 8576 mcgrp = NL80211_MCGRP_VENDOR; 8577 8578 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), skb, 0, 8579 mcgrp, gfp); 8580 } 8581 EXPORT_SYMBOL(__cfg80211_send_event_skb); 8582 8583 #ifdef CONFIG_NL80211_TESTMODE 8584 static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info) 8585 { 8586 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8587 struct wireless_dev *wdev = 8588 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs); 8589 int err; 8590 8591 if (!rdev->ops->testmode_cmd) 8592 return -EOPNOTSUPP; 8593 8594 if (IS_ERR(wdev)) { 8595 err = PTR_ERR(wdev); 8596 if (err != -EINVAL) 8597 return err; 8598 wdev = NULL; 8599 } else if (wdev->wiphy != &rdev->wiphy) { 8600 return -EINVAL; 8601 } 8602 8603 if (!info->attrs[NL80211_ATTR_TESTDATA]) 8604 return -EINVAL; 8605 8606 rdev->cur_cmd_info = info; 8607 err = rdev_testmode_cmd(rdev, wdev, 8608 nla_data(info->attrs[NL80211_ATTR_TESTDATA]), 8609 nla_len(info->attrs[NL80211_ATTR_TESTDATA])); 8610 rdev->cur_cmd_info = NULL; 8611 8612 return err; 8613 } 8614 8615 static int nl80211_testmode_dump(struct sk_buff *skb, 8616 struct netlink_callback *cb) 8617 { 8618 struct cfg80211_registered_device *rdev; 8619 int err; 8620 long phy_idx; 8621 void *data = NULL; 8622 int data_len = 0; 8623 8624 rtnl_lock(); 8625 8626 if (cb->args[0]) { 8627 /* 8628 * 0 is a valid index, but not valid for args[0], 8629 * so we need to offset by 1. 8630 */ 8631 phy_idx = cb->args[0] - 1; 8632 8633 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx); 8634 if (!rdev) { 8635 err = -ENOENT; 8636 goto out_err; 8637 } 8638 } else { 8639 struct nlattr **attrbuf = genl_family_attrbuf(&nl80211_fam); 8640 8641 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, 8642 attrbuf, nl80211_fam.maxattr, nl80211_policy); 8643 if (err) 8644 goto out_err; 8645 8646 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf); 8647 if (IS_ERR(rdev)) { 8648 err = PTR_ERR(rdev); 8649 goto out_err; 8650 } 8651 phy_idx = rdev->wiphy_idx; 8652 8653 if (attrbuf[NL80211_ATTR_TESTDATA]) 8654 cb->args[1] = (long)attrbuf[NL80211_ATTR_TESTDATA]; 8655 } 8656 8657 if (cb->args[1]) { 8658 data = nla_data((void *)cb->args[1]); 8659 data_len = nla_len((void *)cb->args[1]); 8660 } 8661 8662 if (!rdev->ops->testmode_dump) { 8663 err = -EOPNOTSUPP; 8664 goto out_err; 8665 } 8666 8667 while (1) { 8668 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid, 8669 cb->nlh->nlmsg_seq, NLM_F_MULTI, 8670 NL80211_CMD_TESTMODE); 8671 struct nlattr *tmdata; 8672 8673 if (!hdr) 8674 break; 8675 8676 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) { 8677 genlmsg_cancel(skb, hdr); 8678 break; 8679 } 8680 8681 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA); 8682 if (!tmdata) { 8683 genlmsg_cancel(skb, hdr); 8684 break; 8685 } 8686 err = rdev_testmode_dump(rdev, skb, cb, data, data_len); 8687 nla_nest_end(skb, tmdata); 8688 8689 if (err == -ENOBUFS || err == -ENOENT) { 8690 genlmsg_cancel(skb, hdr); 8691 break; 8692 } else if (err) { 8693 genlmsg_cancel(skb, hdr); 8694 goto out_err; 8695 } 8696 8697 genlmsg_end(skb, hdr); 8698 } 8699 8700 err = skb->len; 8701 /* see above */ 8702 cb->args[0] = phy_idx + 1; 8703 out_err: 8704 rtnl_unlock(); 8705 return err; 8706 } 8707 #endif 8708 8709 static int nl80211_connect(struct sk_buff *skb, struct genl_info *info) 8710 { 8711 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8712 struct net_device *dev = info->user_ptr[1]; 8713 struct cfg80211_connect_params connect; 8714 struct wiphy *wiphy; 8715 struct cfg80211_cached_keys *connkeys = NULL; 8716 int err; 8717 8718 memset(&connect, 0, sizeof(connect)); 8719 8720 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8721 return -EINVAL; 8722 8723 if (!info->attrs[NL80211_ATTR_SSID] || 8724 !nla_len(info->attrs[NL80211_ATTR_SSID])) 8725 return -EINVAL; 8726 8727 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) { 8728 connect.auth_type = 8729 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]); 8730 if (!nl80211_valid_auth_type(rdev, connect.auth_type, 8731 NL80211_CMD_CONNECT)) 8732 return -EINVAL; 8733 } else 8734 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC; 8735 8736 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY]; 8737 8738 err = nl80211_crypto_settings(rdev, info, &connect.crypto, 8739 NL80211_MAX_NR_CIPHER_SUITES); 8740 if (err) 8741 return err; 8742 8743 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8744 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8745 return -EOPNOTSUPP; 8746 8747 wiphy = &rdev->wiphy; 8748 8749 connect.bg_scan_period = -1; 8750 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] && 8751 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) { 8752 connect.bg_scan_period = 8753 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]); 8754 } 8755 8756 if (info->attrs[NL80211_ATTR_MAC]) 8757 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8758 else if (info->attrs[NL80211_ATTR_MAC_HINT]) 8759 connect.bssid_hint = 8760 nla_data(info->attrs[NL80211_ATTR_MAC_HINT]); 8761 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 8762 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]); 8763 8764 if (info->attrs[NL80211_ATTR_IE]) { 8765 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8766 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8767 } 8768 8769 if (info->attrs[NL80211_ATTR_USE_MFP]) { 8770 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]); 8771 if (connect.mfp != NL80211_MFP_REQUIRED && 8772 connect.mfp != NL80211_MFP_NO) 8773 return -EINVAL; 8774 } else { 8775 connect.mfp = NL80211_MFP_NO; 8776 } 8777 8778 if (info->attrs[NL80211_ATTR_PREV_BSSID]) 8779 connect.prev_bssid = 8780 nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]); 8781 8782 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 8783 connect.channel = nl80211_get_valid_chan( 8784 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ]); 8785 if (!connect.channel) 8786 return -EINVAL; 8787 } else if (info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]) { 8788 connect.channel_hint = nl80211_get_valid_chan( 8789 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]); 8790 if (!connect.channel_hint) 8791 return -EINVAL; 8792 } 8793 8794 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) { 8795 connkeys = nl80211_parse_connkeys(rdev, 8796 info->attrs[NL80211_ATTR_KEYS], NULL); 8797 if (IS_ERR(connkeys)) 8798 return PTR_ERR(connkeys); 8799 } 8800 8801 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT])) 8802 connect.flags |= ASSOC_REQ_DISABLE_HT; 8803 8804 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8805 memcpy(&connect.ht_capa_mask, 8806 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]), 8807 sizeof(connect.ht_capa_mask)); 8808 8809 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) { 8810 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) { 8811 kzfree(connkeys); 8812 return -EINVAL; 8813 } 8814 memcpy(&connect.ht_capa, 8815 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]), 8816 sizeof(connect.ht_capa)); 8817 } 8818 8819 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT])) 8820 connect.flags |= ASSOC_REQ_DISABLE_VHT; 8821 8822 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) 8823 memcpy(&connect.vht_capa_mask, 8824 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]), 8825 sizeof(connect.vht_capa_mask)); 8826 8827 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) { 8828 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) { 8829 kzfree(connkeys); 8830 return -EINVAL; 8831 } 8832 memcpy(&connect.vht_capa, 8833 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]), 8834 sizeof(connect.vht_capa)); 8835 } 8836 8837 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) { 8838 if (!((rdev->wiphy.features & 8839 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) && 8840 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) && 8841 !wiphy_ext_feature_isset(&rdev->wiphy, 8842 NL80211_EXT_FEATURE_RRM)) { 8843 kzfree(connkeys); 8844 return -EINVAL; 8845 } 8846 connect.flags |= ASSOC_REQ_USE_RRM; 8847 } 8848 8849 connect.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]); 8850 if (connect.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ]) { 8851 kzfree(connkeys); 8852 return -EOPNOTSUPP; 8853 } 8854 8855 if (info->attrs[NL80211_ATTR_BSS_SELECT]) { 8856 /* bss selection makes no sense if bssid is set */ 8857 if (connect.bssid) { 8858 kzfree(connkeys); 8859 return -EINVAL; 8860 } 8861 8862 err = parse_bss_select(info->attrs[NL80211_ATTR_BSS_SELECT], 8863 wiphy, &connect.bss_select); 8864 if (err) { 8865 kzfree(connkeys); 8866 return err; 8867 } 8868 } 8869 8870 wdev_lock(dev->ieee80211_ptr); 8871 8872 err = cfg80211_connect(rdev, dev, &connect, connkeys, 8873 connect.prev_bssid); 8874 if (err) 8875 kzfree(connkeys); 8876 8877 if (!err && info->attrs[NL80211_ATTR_SOCKET_OWNER]) { 8878 dev->ieee80211_ptr->conn_owner_nlportid = info->snd_portid; 8879 if (connect.bssid) 8880 memcpy(dev->ieee80211_ptr->disconnect_bssid, 8881 connect.bssid, ETH_ALEN); 8882 else 8883 memset(dev->ieee80211_ptr->disconnect_bssid, 8884 0, ETH_ALEN); 8885 } 8886 8887 wdev_unlock(dev->ieee80211_ptr); 8888 8889 return err; 8890 } 8891 8892 static int nl80211_update_connect_params(struct sk_buff *skb, 8893 struct genl_info *info) 8894 { 8895 struct cfg80211_connect_params connect = {}; 8896 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8897 struct net_device *dev = info->user_ptr[1]; 8898 struct wireless_dev *wdev = dev->ieee80211_ptr; 8899 u32 changed = 0; 8900 int ret; 8901 8902 if (!rdev->ops->update_connect_params) 8903 return -EOPNOTSUPP; 8904 8905 if (info->attrs[NL80211_ATTR_IE]) { 8906 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8907 return -EINVAL; 8908 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8909 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8910 changed |= UPDATE_ASSOC_IES; 8911 } 8912 8913 wdev_lock(dev->ieee80211_ptr); 8914 if (!wdev->current_bss) 8915 ret = -ENOLINK; 8916 else 8917 ret = rdev_update_connect_params(rdev, dev, &connect, changed); 8918 wdev_unlock(dev->ieee80211_ptr); 8919 8920 return ret; 8921 } 8922 8923 static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info) 8924 { 8925 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8926 struct net_device *dev = info->user_ptr[1]; 8927 u16 reason; 8928 int ret; 8929 8930 if (!info->attrs[NL80211_ATTR_REASON_CODE]) 8931 reason = WLAN_REASON_DEAUTH_LEAVING; 8932 else 8933 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]); 8934 8935 if (reason == 0) 8936 return -EINVAL; 8937 8938 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8939 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8940 return -EOPNOTSUPP; 8941 8942 wdev_lock(dev->ieee80211_ptr); 8943 ret = cfg80211_disconnect(rdev, dev, reason, true); 8944 wdev_unlock(dev->ieee80211_ptr); 8945 return ret; 8946 } 8947 8948 static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info) 8949 { 8950 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8951 struct net *net; 8952 int err; 8953 8954 if (info->attrs[NL80211_ATTR_PID]) { 8955 u32 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]); 8956 8957 net = get_net_ns_by_pid(pid); 8958 } else if (info->attrs[NL80211_ATTR_NETNS_FD]) { 8959 u32 fd = nla_get_u32(info->attrs[NL80211_ATTR_NETNS_FD]); 8960 8961 net = get_net_ns_by_fd(fd); 8962 } else { 8963 return -EINVAL; 8964 } 8965 8966 if (IS_ERR(net)) 8967 return PTR_ERR(net); 8968 8969 err = 0; 8970 8971 /* check if anything to do */ 8972 if (!net_eq(wiphy_net(&rdev->wiphy), net)) 8973 err = cfg80211_switch_netns(rdev, net); 8974 8975 put_net(net); 8976 return err; 8977 } 8978 8979 static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info) 8980 { 8981 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8982 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev, 8983 struct cfg80211_pmksa *pmksa) = NULL; 8984 struct net_device *dev = info->user_ptr[1]; 8985 struct cfg80211_pmksa pmksa; 8986 8987 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa)); 8988 8989 if (!info->attrs[NL80211_ATTR_MAC]) 8990 return -EINVAL; 8991 8992 if (!info->attrs[NL80211_ATTR_PMKID]) 8993 return -EINVAL; 8994 8995 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]); 8996 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8997 8998 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8999 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 9000 return -EOPNOTSUPP; 9001 9002 switch (info->genlhdr->cmd) { 9003 case NL80211_CMD_SET_PMKSA: 9004 rdev_ops = rdev->ops->set_pmksa; 9005 break; 9006 case NL80211_CMD_DEL_PMKSA: 9007 rdev_ops = rdev->ops->del_pmksa; 9008 break; 9009 default: 9010 WARN_ON(1); 9011 break; 9012 } 9013 9014 if (!rdev_ops) 9015 return -EOPNOTSUPP; 9016 9017 return rdev_ops(&rdev->wiphy, dev, &pmksa); 9018 } 9019 9020 static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info) 9021 { 9022 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9023 struct net_device *dev = info->user_ptr[1]; 9024 9025 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 9026 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 9027 return -EOPNOTSUPP; 9028 9029 if (!rdev->ops->flush_pmksa) 9030 return -EOPNOTSUPP; 9031 9032 return rdev_flush_pmksa(rdev, dev); 9033 } 9034 9035 static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info) 9036 { 9037 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9038 struct net_device *dev = info->user_ptr[1]; 9039 u8 action_code, dialog_token; 9040 u32 peer_capability = 0; 9041 u16 status_code; 9042 u8 *peer; 9043 bool initiator; 9044 9045 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) || 9046 !rdev->ops->tdls_mgmt) 9047 return -EOPNOTSUPP; 9048 9049 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] || 9050 !info->attrs[NL80211_ATTR_STATUS_CODE] || 9051 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] || 9052 !info->attrs[NL80211_ATTR_IE] || 9053 !info->attrs[NL80211_ATTR_MAC]) 9054 return -EINVAL; 9055 9056 peer = nla_data(info->attrs[NL80211_ATTR_MAC]); 9057 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]); 9058 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]); 9059 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]); 9060 initiator = nla_get_flag(info->attrs[NL80211_ATTR_TDLS_INITIATOR]); 9061 if (info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY]) 9062 peer_capability = 9063 nla_get_u32(info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY]); 9064 9065 return rdev_tdls_mgmt(rdev, dev, peer, action_code, 9066 dialog_token, status_code, peer_capability, 9067 initiator, 9068 nla_data(info->attrs[NL80211_ATTR_IE]), 9069 nla_len(info->attrs[NL80211_ATTR_IE])); 9070 } 9071 9072 static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info) 9073 { 9074 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9075 struct net_device *dev = info->user_ptr[1]; 9076 enum nl80211_tdls_operation operation; 9077 u8 *peer; 9078 9079 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) || 9080 !rdev->ops->tdls_oper) 9081 return -EOPNOTSUPP; 9082 9083 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] || 9084 !info->attrs[NL80211_ATTR_MAC]) 9085 return -EINVAL; 9086 9087 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]); 9088 peer = nla_data(info->attrs[NL80211_ATTR_MAC]); 9089 9090 return rdev_tdls_oper(rdev, dev, peer, operation); 9091 } 9092 9093 static int nl80211_remain_on_channel(struct sk_buff *skb, 9094 struct genl_info *info) 9095 { 9096 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9097 struct wireless_dev *wdev = info->user_ptr[1]; 9098 struct cfg80211_chan_def chandef; 9099 struct sk_buff *msg; 9100 void *hdr; 9101 u64 cookie; 9102 u32 duration; 9103 int err; 9104 9105 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] || 9106 !info->attrs[NL80211_ATTR_DURATION]) 9107 return -EINVAL; 9108 9109 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]); 9110 9111 if (!rdev->ops->remain_on_channel || 9112 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)) 9113 return -EOPNOTSUPP; 9114 9115 /* 9116 * We should be on that channel for at least a minimum amount of 9117 * time (10ms) but no longer than the driver supports. 9118 */ 9119 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME || 9120 duration > rdev->wiphy.max_remain_on_channel_duration) 9121 return -EINVAL; 9122 9123 err = nl80211_parse_chandef(rdev, info, &chandef); 9124 if (err) 9125 return err; 9126 9127 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 9128 if (!msg) 9129 return -ENOMEM; 9130 9131 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 9132 NL80211_CMD_REMAIN_ON_CHANNEL); 9133 if (!hdr) { 9134 err = -ENOBUFS; 9135 goto free_msg; 9136 } 9137 9138 err = rdev_remain_on_channel(rdev, wdev, chandef.chan, 9139 duration, &cookie); 9140 9141 if (err) 9142 goto free_msg; 9143 9144 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 9145 NL80211_ATTR_PAD)) 9146 goto nla_put_failure; 9147 9148 genlmsg_end(msg, hdr); 9149 9150 return genlmsg_reply(msg, info); 9151 9152 nla_put_failure: 9153 err = -ENOBUFS; 9154 free_msg: 9155 nlmsg_free(msg); 9156 return err; 9157 } 9158 9159 static int nl80211_cancel_remain_on_channel(struct sk_buff *skb, 9160 struct genl_info *info) 9161 { 9162 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9163 struct wireless_dev *wdev = info->user_ptr[1]; 9164 u64 cookie; 9165 9166 if (!info->attrs[NL80211_ATTR_COOKIE]) 9167 return -EINVAL; 9168 9169 if (!rdev->ops->cancel_remain_on_channel) 9170 return -EOPNOTSUPP; 9171 9172 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]); 9173 9174 return rdev_cancel_remain_on_channel(rdev, wdev, cookie); 9175 } 9176 9177 static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb, 9178 struct genl_info *info) 9179 { 9180 struct cfg80211_bitrate_mask mask; 9181 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9182 struct net_device *dev = info->user_ptr[1]; 9183 int err; 9184 9185 if (!rdev->ops->set_bitrate_mask) 9186 return -EOPNOTSUPP; 9187 9188 err = nl80211_parse_tx_bitrate_mask(info, &mask); 9189 if (err) 9190 return err; 9191 9192 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask); 9193 } 9194 9195 static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info) 9196 { 9197 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9198 struct wireless_dev *wdev = info->user_ptr[1]; 9199 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION; 9200 9201 if (!info->attrs[NL80211_ATTR_FRAME_MATCH]) 9202 return -EINVAL; 9203 9204 if (info->attrs[NL80211_ATTR_FRAME_TYPE]) 9205 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]); 9206 9207 switch (wdev->iftype) { 9208 case NL80211_IFTYPE_STATION: 9209 case NL80211_IFTYPE_ADHOC: 9210 case NL80211_IFTYPE_P2P_CLIENT: 9211 case NL80211_IFTYPE_AP: 9212 case NL80211_IFTYPE_AP_VLAN: 9213 case NL80211_IFTYPE_MESH_POINT: 9214 case NL80211_IFTYPE_P2P_GO: 9215 case NL80211_IFTYPE_P2P_DEVICE: 9216 break; 9217 case NL80211_IFTYPE_NAN: 9218 default: 9219 return -EOPNOTSUPP; 9220 } 9221 9222 /* not much point in registering if we can't reply */ 9223 if (!rdev->ops->mgmt_tx) 9224 return -EOPNOTSUPP; 9225 9226 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type, 9227 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]), 9228 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH])); 9229 } 9230 9231 static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info) 9232 { 9233 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9234 struct wireless_dev *wdev = info->user_ptr[1]; 9235 struct cfg80211_chan_def chandef; 9236 int err; 9237 void *hdr = NULL; 9238 u64 cookie; 9239 struct sk_buff *msg = NULL; 9240 struct cfg80211_mgmt_tx_params params = { 9241 .dont_wait_for_ack = 9242 info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK], 9243 }; 9244 9245 if (!info->attrs[NL80211_ATTR_FRAME]) 9246 return -EINVAL; 9247 9248 if (!rdev->ops->mgmt_tx) 9249 return -EOPNOTSUPP; 9250 9251 switch (wdev->iftype) { 9252 case NL80211_IFTYPE_P2P_DEVICE: 9253 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ]) 9254 return -EINVAL; 9255 case NL80211_IFTYPE_STATION: 9256 case NL80211_IFTYPE_ADHOC: 9257 case NL80211_IFTYPE_P2P_CLIENT: 9258 case NL80211_IFTYPE_AP: 9259 case NL80211_IFTYPE_AP_VLAN: 9260 case NL80211_IFTYPE_MESH_POINT: 9261 case NL80211_IFTYPE_P2P_GO: 9262 break; 9263 case NL80211_IFTYPE_NAN: 9264 default: 9265 return -EOPNOTSUPP; 9266 } 9267 9268 if (info->attrs[NL80211_ATTR_DURATION]) { 9269 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX)) 9270 return -EINVAL; 9271 params.wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]); 9272 9273 /* 9274 * We should wait on the channel for at least a minimum amount 9275 * of time (10ms) but no longer than the driver supports. 9276 */ 9277 if (params.wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME || 9278 params.wait > rdev->wiphy.max_remain_on_channel_duration) 9279 return -EINVAL; 9280 } 9281 9282 params.offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK]; 9283 9284 if (params.offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX)) 9285 return -EINVAL; 9286 9287 params.no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]); 9288 9289 /* get the channel if any has been specified, otherwise pass NULL to 9290 * the driver. The latter will use the current one 9291 */ 9292 chandef.chan = NULL; 9293 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 9294 err = nl80211_parse_chandef(rdev, info, &chandef); 9295 if (err) 9296 return err; 9297 } 9298 9299 if (!chandef.chan && params.offchan) 9300 return -EINVAL; 9301 9302 params.buf = nla_data(info->attrs[NL80211_ATTR_FRAME]); 9303 params.len = nla_len(info->attrs[NL80211_ATTR_FRAME]); 9304 9305 if (info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]) { 9306 int len = nla_len(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]); 9307 int i; 9308 9309 if (len % sizeof(u16)) 9310 return -EINVAL; 9311 9312 params.n_csa_offsets = len / sizeof(u16); 9313 params.csa_offsets = 9314 nla_data(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]); 9315 9316 /* check that all the offsets fit the frame */ 9317 for (i = 0; i < params.n_csa_offsets; i++) { 9318 if (params.csa_offsets[i] >= params.len) 9319 return -EINVAL; 9320 } 9321 } 9322 9323 if (!params.dont_wait_for_ack) { 9324 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 9325 if (!msg) 9326 return -ENOMEM; 9327 9328 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 9329 NL80211_CMD_FRAME); 9330 if (!hdr) { 9331 err = -ENOBUFS; 9332 goto free_msg; 9333 } 9334 } 9335 9336 params.chan = chandef.chan; 9337 err = cfg80211_mlme_mgmt_tx(rdev, wdev, ¶ms, &cookie); 9338 if (err) 9339 goto free_msg; 9340 9341 if (msg) { 9342 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 9343 NL80211_ATTR_PAD)) 9344 goto nla_put_failure; 9345 9346 genlmsg_end(msg, hdr); 9347 return genlmsg_reply(msg, info); 9348 } 9349 9350 return 0; 9351 9352 nla_put_failure: 9353 err = -ENOBUFS; 9354 free_msg: 9355 nlmsg_free(msg); 9356 return err; 9357 } 9358 9359 static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info) 9360 { 9361 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9362 struct wireless_dev *wdev = info->user_ptr[1]; 9363 u64 cookie; 9364 9365 if (!info->attrs[NL80211_ATTR_COOKIE]) 9366 return -EINVAL; 9367 9368 if (!rdev->ops->mgmt_tx_cancel_wait) 9369 return -EOPNOTSUPP; 9370 9371 switch (wdev->iftype) { 9372 case NL80211_IFTYPE_STATION: 9373 case NL80211_IFTYPE_ADHOC: 9374 case NL80211_IFTYPE_P2P_CLIENT: 9375 case NL80211_IFTYPE_AP: 9376 case NL80211_IFTYPE_AP_VLAN: 9377 case NL80211_IFTYPE_P2P_GO: 9378 case NL80211_IFTYPE_P2P_DEVICE: 9379 break; 9380 case NL80211_IFTYPE_NAN: 9381 default: 9382 return -EOPNOTSUPP; 9383 } 9384 9385 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]); 9386 9387 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie); 9388 } 9389 9390 static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info) 9391 { 9392 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9393 struct wireless_dev *wdev; 9394 struct net_device *dev = info->user_ptr[1]; 9395 u8 ps_state; 9396 bool state; 9397 int err; 9398 9399 if (!info->attrs[NL80211_ATTR_PS_STATE]) 9400 return -EINVAL; 9401 9402 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]); 9403 9404 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED) 9405 return -EINVAL; 9406 9407 wdev = dev->ieee80211_ptr; 9408 9409 if (!rdev->ops->set_power_mgmt) 9410 return -EOPNOTSUPP; 9411 9412 state = (ps_state == NL80211_PS_ENABLED) ? true : false; 9413 9414 if (state == wdev->ps) 9415 return 0; 9416 9417 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout); 9418 if (!err) 9419 wdev->ps = state; 9420 return err; 9421 } 9422 9423 static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info) 9424 { 9425 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9426 enum nl80211_ps_state ps_state; 9427 struct wireless_dev *wdev; 9428 struct net_device *dev = info->user_ptr[1]; 9429 struct sk_buff *msg; 9430 void *hdr; 9431 int err; 9432 9433 wdev = dev->ieee80211_ptr; 9434 9435 if (!rdev->ops->set_power_mgmt) 9436 return -EOPNOTSUPP; 9437 9438 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 9439 if (!msg) 9440 return -ENOMEM; 9441 9442 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 9443 NL80211_CMD_GET_POWER_SAVE); 9444 if (!hdr) { 9445 err = -ENOBUFS; 9446 goto free_msg; 9447 } 9448 9449 if (wdev->ps) 9450 ps_state = NL80211_PS_ENABLED; 9451 else 9452 ps_state = NL80211_PS_DISABLED; 9453 9454 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state)) 9455 goto nla_put_failure; 9456 9457 genlmsg_end(msg, hdr); 9458 return genlmsg_reply(msg, info); 9459 9460 nla_put_failure: 9461 err = -ENOBUFS; 9462 free_msg: 9463 nlmsg_free(msg); 9464 return err; 9465 } 9466 9467 static const struct nla_policy 9468 nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] = { 9469 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 }, 9470 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 }, 9471 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 }, 9472 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 }, 9473 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 }, 9474 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 }, 9475 [NL80211_ATTR_CQM_RSSI_LEVEL] = { .type = NLA_S32 }, 9476 }; 9477 9478 static int nl80211_set_cqm_txe(struct genl_info *info, 9479 u32 rate, u32 pkts, u32 intvl) 9480 { 9481 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9482 struct net_device *dev = info->user_ptr[1]; 9483 struct wireless_dev *wdev = dev->ieee80211_ptr; 9484 9485 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL) 9486 return -EINVAL; 9487 9488 if (!rdev->ops->set_cqm_txe_config) 9489 return -EOPNOTSUPP; 9490 9491 if (wdev->iftype != NL80211_IFTYPE_STATION && 9492 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT) 9493 return -EOPNOTSUPP; 9494 9495 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl); 9496 } 9497 9498 static int nl80211_set_cqm_rssi(struct genl_info *info, 9499 s32 threshold, u32 hysteresis) 9500 { 9501 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9502 struct net_device *dev = info->user_ptr[1]; 9503 struct wireless_dev *wdev = dev->ieee80211_ptr; 9504 9505 if (threshold > 0) 9506 return -EINVAL; 9507 9508 /* disabling - hysteresis should also be zero then */ 9509 if (threshold == 0) 9510 hysteresis = 0; 9511 9512 if (!rdev->ops->set_cqm_rssi_config) 9513 return -EOPNOTSUPP; 9514 9515 if (wdev->iftype != NL80211_IFTYPE_STATION && 9516 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT) 9517 return -EOPNOTSUPP; 9518 9519 return rdev_set_cqm_rssi_config(rdev, dev, threshold, hysteresis); 9520 } 9521 9522 static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info) 9523 { 9524 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1]; 9525 struct nlattr *cqm; 9526 int err; 9527 9528 cqm = info->attrs[NL80211_ATTR_CQM]; 9529 if (!cqm) 9530 return -EINVAL; 9531 9532 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm, 9533 nl80211_attr_cqm_policy); 9534 if (err) 9535 return err; 9536 9537 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] && 9538 attrs[NL80211_ATTR_CQM_RSSI_HYST]) { 9539 s32 threshold = nla_get_s32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]); 9540 u32 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]); 9541 9542 return nl80211_set_cqm_rssi(info, threshold, hysteresis); 9543 } 9544 9545 if (attrs[NL80211_ATTR_CQM_TXE_RATE] && 9546 attrs[NL80211_ATTR_CQM_TXE_PKTS] && 9547 attrs[NL80211_ATTR_CQM_TXE_INTVL]) { 9548 u32 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]); 9549 u32 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]); 9550 u32 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]); 9551 9552 return nl80211_set_cqm_txe(info, rate, pkts, intvl); 9553 } 9554 9555 return -EINVAL; 9556 } 9557 9558 static int nl80211_join_ocb(struct sk_buff *skb, struct genl_info *info) 9559 { 9560 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9561 struct net_device *dev = info->user_ptr[1]; 9562 struct ocb_setup setup = {}; 9563 int err; 9564 9565 err = nl80211_parse_chandef(rdev, info, &setup.chandef); 9566 if (err) 9567 return err; 9568 9569 return cfg80211_join_ocb(rdev, dev, &setup); 9570 } 9571 9572 static int nl80211_leave_ocb(struct sk_buff *skb, struct genl_info *info) 9573 { 9574 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9575 struct net_device *dev = info->user_ptr[1]; 9576 9577 return cfg80211_leave_ocb(rdev, dev); 9578 } 9579 9580 static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info) 9581 { 9582 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9583 struct net_device *dev = info->user_ptr[1]; 9584 struct mesh_config cfg; 9585 struct mesh_setup setup; 9586 int err; 9587 9588 /* start with default */ 9589 memcpy(&cfg, &default_mesh_config, sizeof(cfg)); 9590 memcpy(&setup, &default_mesh_setup, sizeof(setup)); 9591 9592 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) { 9593 /* and parse parameters if given */ 9594 err = nl80211_parse_mesh_config(info, &cfg, NULL); 9595 if (err) 9596 return err; 9597 } 9598 9599 if (!info->attrs[NL80211_ATTR_MESH_ID] || 9600 !nla_len(info->attrs[NL80211_ATTR_MESH_ID])) 9601 return -EINVAL; 9602 9603 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]); 9604 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]); 9605 9606 if (info->attrs[NL80211_ATTR_MCAST_RATE] && 9607 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate, 9608 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]))) 9609 return -EINVAL; 9610 9611 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) { 9612 setup.beacon_interval = 9613 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]); 9614 9615 err = cfg80211_validate_beacon_int(rdev, 9616 NL80211_IFTYPE_MESH_POINT, 9617 setup.beacon_interval); 9618 if (err) 9619 return err; 9620 } 9621 9622 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) { 9623 setup.dtim_period = 9624 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]); 9625 if (setup.dtim_period < 1 || setup.dtim_period > 100) 9626 return -EINVAL; 9627 } 9628 9629 if (info->attrs[NL80211_ATTR_MESH_SETUP]) { 9630 /* parse additional setup parameters if given */ 9631 err = nl80211_parse_mesh_setup(info, &setup); 9632 if (err) 9633 return err; 9634 } 9635 9636 if (setup.user_mpm) 9637 cfg.auto_open_plinks = false; 9638 9639 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 9640 err = nl80211_parse_chandef(rdev, info, &setup.chandef); 9641 if (err) 9642 return err; 9643 } else { 9644 /* cfg80211_join_mesh() will sort it out */ 9645 setup.chandef.chan = NULL; 9646 } 9647 9648 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) { 9649 u8 *rates = nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 9650 int n_rates = 9651 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 9652 struct ieee80211_supported_band *sband; 9653 9654 if (!setup.chandef.chan) 9655 return -EINVAL; 9656 9657 sband = rdev->wiphy.bands[setup.chandef.chan->band]; 9658 9659 err = ieee80211_get_ratemask(sband, rates, n_rates, 9660 &setup.basic_rates); 9661 if (err) 9662 return err; 9663 } 9664 9665 if (info->attrs[NL80211_ATTR_TX_RATES]) { 9666 err = nl80211_parse_tx_bitrate_mask(info, &setup.beacon_rate); 9667 if (err) 9668 return err; 9669 9670 err = validate_beacon_tx_rate(rdev, setup.chandef.chan->band, 9671 &setup.beacon_rate); 9672 if (err) 9673 return err; 9674 } 9675 9676 return cfg80211_join_mesh(rdev, dev, &setup, &cfg); 9677 } 9678 9679 static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info) 9680 { 9681 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9682 struct net_device *dev = info->user_ptr[1]; 9683 9684 return cfg80211_leave_mesh(rdev, dev); 9685 } 9686 9687 #ifdef CONFIG_PM 9688 static int nl80211_send_wowlan_patterns(struct sk_buff *msg, 9689 struct cfg80211_registered_device *rdev) 9690 { 9691 struct cfg80211_wowlan *wowlan = rdev->wiphy.wowlan_config; 9692 struct nlattr *nl_pats, *nl_pat; 9693 int i, pat_len; 9694 9695 if (!wowlan->n_patterns) 9696 return 0; 9697 9698 nl_pats = nla_nest_start(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN); 9699 if (!nl_pats) 9700 return -ENOBUFS; 9701 9702 for (i = 0; i < wowlan->n_patterns; i++) { 9703 nl_pat = nla_nest_start(msg, i + 1); 9704 if (!nl_pat) 9705 return -ENOBUFS; 9706 pat_len = wowlan->patterns[i].pattern_len; 9707 if (nla_put(msg, NL80211_PKTPAT_MASK, DIV_ROUND_UP(pat_len, 8), 9708 wowlan->patterns[i].mask) || 9709 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len, 9710 wowlan->patterns[i].pattern) || 9711 nla_put_u32(msg, NL80211_PKTPAT_OFFSET, 9712 wowlan->patterns[i].pkt_offset)) 9713 return -ENOBUFS; 9714 nla_nest_end(msg, nl_pat); 9715 } 9716 nla_nest_end(msg, nl_pats); 9717 9718 return 0; 9719 } 9720 9721 static int nl80211_send_wowlan_tcp(struct sk_buff *msg, 9722 struct cfg80211_wowlan_tcp *tcp) 9723 { 9724 struct nlattr *nl_tcp; 9725 9726 if (!tcp) 9727 return 0; 9728 9729 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION); 9730 if (!nl_tcp) 9731 return -ENOBUFS; 9732 9733 if (nla_put_in_addr(msg, NL80211_WOWLAN_TCP_SRC_IPV4, tcp->src) || 9734 nla_put_in_addr(msg, NL80211_WOWLAN_TCP_DST_IPV4, tcp->dst) || 9735 nla_put(msg, NL80211_WOWLAN_TCP_DST_MAC, ETH_ALEN, tcp->dst_mac) || 9736 nla_put_u16(msg, NL80211_WOWLAN_TCP_SRC_PORT, tcp->src_port) || 9737 nla_put_u16(msg, NL80211_WOWLAN_TCP_DST_PORT, tcp->dst_port) || 9738 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD, 9739 tcp->payload_len, tcp->payload) || 9740 nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL, 9741 tcp->data_interval) || 9742 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD, 9743 tcp->wake_len, tcp->wake_data) || 9744 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_MASK, 9745 DIV_ROUND_UP(tcp->wake_len, 8), tcp->wake_mask)) 9746 return -ENOBUFS; 9747 9748 if (tcp->payload_seq.len && 9749 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ, 9750 sizeof(tcp->payload_seq), &tcp->payload_seq)) 9751 return -ENOBUFS; 9752 9753 if (tcp->payload_tok.len && 9754 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN, 9755 sizeof(tcp->payload_tok) + tcp->tokens_size, 9756 &tcp->payload_tok)) 9757 return -ENOBUFS; 9758 9759 nla_nest_end(msg, nl_tcp); 9760 9761 return 0; 9762 } 9763 9764 static int nl80211_send_wowlan_nd(struct sk_buff *msg, 9765 struct cfg80211_sched_scan_request *req) 9766 { 9767 struct nlattr *nd, *freqs, *matches, *match, *scan_plans, *scan_plan; 9768 int i; 9769 9770 if (!req) 9771 return 0; 9772 9773 nd = nla_nest_start(msg, NL80211_WOWLAN_TRIG_NET_DETECT); 9774 if (!nd) 9775 return -ENOBUFS; 9776 9777 if (req->n_scan_plans == 1 && 9778 nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_INTERVAL, 9779 req->scan_plans[0].interval * 1000)) 9780 return -ENOBUFS; 9781 9782 if (nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_DELAY, req->delay)) 9783 return -ENOBUFS; 9784 9785 if (req->relative_rssi_set) { 9786 struct nl80211_bss_select_rssi_adjust rssi_adjust; 9787 9788 if (nla_put_s8(msg, NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI, 9789 req->relative_rssi)) 9790 return -ENOBUFS; 9791 9792 rssi_adjust.band = req->rssi_adjust.band; 9793 rssi_adjust.delta = req->rssi_adjust.delta; 9794 if (nla_put(msg, NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST, 9795 sizeof(rssi_adjust), &rssi_adjust)) 9796 return -ENOBUFS; 9797 } 9798 9799 freqs = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES); 9800 if (!freqs) 9801 return -ENOBUFS; 9802 9803 for (i = 0; i < req->n_channels; i++) { 9804 if (nla_put_u32(msg, i, req->channels[i]->center_freq)) 9805 return -ENOBUFS; 9806 } 9807 9808 nla_nest_end(msg, freqs); 9809 9810 if (req->n_match_sets) { 9811 matches = nla_nest_start(msg, NL80211_ATTR_SCHED_SCAN_MATCH); 9812 if (!matches) 9813 return -ENOBUFS; 9814 9815 for (i = 0; i < req->n_match_sets; i++) { 9816 match = nla_nest_start(msg, i); 9817 if (!match) 9818 return -ENOBUFS; 9819 9820 if (nla_put(msg, NL80211_SCHED_SCAN_MATCH_ATTR_SSID, 9821 req->match_sets[i].ssid.ssid_len, 9822 req->match_sets[i].ssid.ssid)) 9823 return -ENOBUFS; 9824 nla_nest_end(msg, match); 9825 } 9826 nla_nest_end(msg, matches); 9827 } 9828 9829 scan_plans = nla_nest_start(msg, NL80211_ATTR_SCHED_SCAN_PLANS); 9830 if (!scan_plans) 9831 return -ENOBUFS; 9832 9833 for (i = 0; i < req->n_scan_plans; i++) { 9834 scan_plan = nla_nest_start(msg, i + 1); 9835 if (!scan_plan) 9836 return -ENOBUFS; 9837 9838 if (!scan_plan || 9839 nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_INTERVAL, 9840 req->scan_plans[i].interval) || 9841 (req->scan_plans[i].iterations && 9842 nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_ITERATIONS, 9843 req->scan_plans[i].iterations))) 9844 return -ENOBUFS; 9845 nla_nest_end(msg, scan_plan); 9846 } 9847 nla_nest_end(msg, scan_plans); 9848 9849 nla_nest_end(msg, nd); 9850 9851 return 0; 9852 } 9853 9854 static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info) 9855 { 9856 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9857 struct sk_buff *msg; 9858 void *hdr; 9859 u32 size = NLMSG_DEFAULT_SIZE; 9860 9861 if (!rdev->wiphy.wowlan) 9862 return -EOPNOTSUPP; 9863 9864 if (rdev->wiphy.wowlan_config && rdev->wiphy.wowlan_config->tcp) { 9865 /* adjust size to have room for all the data */ 9866 size += rdev->wiphy.wowlan_config->tcp->tokens_size + 9867 rdev->wiphy.wowlan_config->tcp->payload_len + 9868 rdev->wiphy.wowlan_config->tcp->wake_len + 9869 rdev->wiphy.wowlan_config->tcp->wake_len / 8; 9870 } 9871 9872 msg = nlmsg_new(size, GFP_KERNEL); 9873 if (!msg) 9874 return -ENOMEM; 9875 9876 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 9877 NL80211_CMD_GET_WOWLAN); 9878 if (!hdr) 9879 goto nla_put_failure; 9880 9881 if (rdev->wiphy.wowlan_config) { 9882 struct nlattr *nl_wowlan; 9883 9884 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS); 9885 if (!nl_wowlan) 9886 goto nla_put_failure; 9887 9888 if ((rdev->wiphy.wowlan_config->any && 9889 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) || 9890 (rdev->wiphy.wowlan_config->disconnect && 9891 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) || 9892 (rdev->wiphy.wowlan_config->magic_pkt && 9893 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) || 9894 (rdev->wiphy.wowlan_config->gtk_rekey_failure && 9895 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) || 9896 (rdev->wiphy.wowlan_config->eap_identity_req && 9897 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) || 9898 (rdev->wiphy.wowlan_config->four_way_handshake && 9899 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) || 9900 (rdev->wiphy.wowlan_config->rfkill_release && 9901 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))) 9902 goto nla_put_failure; 9903 9904 if (nl80211_send_wowlan_patterns(msg, rdev)) 9905 goto nla_put_failure; 9906 9907 if (nl80211_send_wowlan_tcp(msg, 9908 rdev->wiphy.wowlan_config->tcp)) 9909 goto nla_put_failure; 9910 9911 if (nl80211_send_wowlan_nd( 9912 msg, 9913 rdev->wiphy.wowlan_config->nd_config)) 9914 goto nla_put_failure; 9915 9916 nla_nest_end(msg, nl_wowlan); 9917 } 9918 9919 genlmsg_end(msg, hdr); 9920 return genlmsg_reply(msg, info); 9921 9922 nla_put_failure: 9923 nlmsg_free(msg); 9924 return -ENOBUFS; 9925 } 9926 9927 static int nl80211_parse_wowlan_tcp(struct cfg80211_registered_device *rdev, 9928 struct nlattr *attr, 9929 struct cfg80211_wowlan *trig) 9930 { 9931 struct nlattr *tb[NUM_NL80211_WOWLAN_TCP]; 9932 struct cfg80211_wowlan_tcp *cfg; 9933 struct nl80211_wowlan_tcp_data_token *tok = NULL; 9934 struct nl80211_wowlan_tcp_data_seq *seq = NULL; 9935 u32 size; 9936 u32 data_size, wake_size, tokens_size = 0, wake_mask_size; 9937 int err, port; 9938 9939 if (!rdev->wiphy.wowlan->tcp) 9940 return -EINVAL; 9941 9942 err = nla_parse_nested(tb, MAX_NL80211_WOWLAN_TCP, attr, 9943 nl80211_wowlan_tcp_policy); 9944 if (err) 9945 return err; 9946 9947 if (!tb[NL80211_WOWLAN_TCP_SRC_IPV4] || 9948 !tb[NL80211_WOWLAN_TCP_DST_IPV4] || 9949 !tb[NL80211_WOWLAN_TCP_DST_MAC] || 9950 !tb[NL80211_WOWLAN_TCP_DST_PORT] || 9951 !tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD] || 9952 !tb[NL80211_WOWLAN_TCP_DATA_INTERVAL] || 9953 !tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] || 9954 !tb[NL80211_WOWLAN_TCP_WAKE_MASK]) 9955 return -EINVAL; 9956 9957 data_size = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]); 9958 if (data_size > rdev->wiphy.wowlan->tcp->data_payload_max) 9959 return -EINVAL; 9960 9961 if (nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) > 9962 rdev->wiphy.wowlan->tcp->data_interval_max || 9963 nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) == 0) 9964 return -EINVAL; 9965 9966 wake_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]); 9967 if (wake_size > rdev->wiphy.wowlan->tcp->wake_payload_max) 9968 return -EINVAL; 9969 9970 wake_mask_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_MASK]); 9971 if (wake_mask_size != DIV_ROUND_UP(wake_size, 8)) 9972 return -EINVAL; 9973 9974 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]) { 9975 u32 tokln = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]); 9976 9977 tok = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]); 9978 tokens_size = tokln - sizeof(*tok); 9979 9980 if (!tok->len || tokens_size % tok->len) 9981 return -EINVAL; 9982 if (!rdev->wiphy.wowlan->tcp->tok) 9983 return -EINVAL; 9984 if (tok->len > rdev->wiphy.wowlan->tcp->tok->max_len) 9985 return -EINVAL; 9986 if (tok->len < rdev->wiphy.wowlan->tcp->tok->min_len) 9987 return -EINVAL; 9988 if (tokens_size > rdev->wiphy.wowlan->tcp->tok->bufsize) 9989 return -EINVAL; 9990 if (tok->offset + tok->len > data_size) 9991 return -EINVAL; 9992 } 9993 9994 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]) { 9995 seq = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]); 9996 if (!rdev->wiphy.wowlan->tcp->seq) 9997 return -EINVAL; 9998 if (seq->len == 0 || seq->len > 4) 9999 return -EINVAL; 10000 if (seq->len + seq->offset > data_size) 10001 return -EINVAL; 10002 } 10003 10004 size = sizeof(*cfg); 10005 size += data_size; 10006 size += wake_size + wake_mask_size; 10007 size += tokens_size; 10008 10009 cfg = kzalloc(size, GFP_KERNEL); 10010 if (!cfg) 10011 return -ENOMEM; 10012 cfg->src = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_SRC_IPV4]); 10013 cfg->dst = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_DST_IPV4]); 10014 memcpy(cfg->dst_mac, nla_data(tb[NL80211_WOWLAN_TCP_DST_MAC]), 10015 ETH_ALEN); 10016 if (tb[NL80211_WOWLAN_TCP_SRC_PORT]) 10017 port = nla_get_u16(tb[NL80211_WOWLAN_TCP_SRC_PORT]); 10018 else 10019 port = 0; 10020 #ifdef CONFIG_INET 10021 /* allocate a socket and port for it and use it */ 10022 err = __sock_create(wiphy_net(&rdev->wiphy), PF_INET, SOCK_STREAM, 10023 IPPROTO_TCP, &cfg->sock, 1); 10024 if (err) { 10025 kfree(cfg); 10026 return err; 10027 } 10028 if (inet_csk_get_port(cfg->sock->sk, port)) { 10029 sock_release(cfg->sock); 10030 kfree(cfg); 10031 return -EADDRINUSE; 10032 } 10033 cfg->src_port = inet_sk(cfg->sock->sk)->inet_num; 10034 #else 10035 if (!port) { 10036 kfree(cfg); 10037 return -EINVAL; 10038 } 10039 cfg->src_port = port; 10040 #endif 10041 10042 cfg->dst_port = nla_get_u16(tb[NL80211_WOWLAN_TCP_DST_PORT]); 10043 cfg->payload_len = data_size; 10044 cfg->payload = (u8 *)cfg + sizeof(*cfg) + tokens_size; 10045 memcpy((void *)cfg->payload, 10046 nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]), 10047 data_size); 10048 if (seq) 10049 cfg->payload_seq = *seq; 10050 cfg->data_interval = nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]); 10051 cfg->wake_len = wake_size; 10052 cfg->wake_data = (u8 *)cfg + sizeof(*cfg) + tokens_size + data_size; 10053 memcpy((void *)cfg->wake_data, 10054 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]), 10055 wake_size); 10056 cfg->wake_mask = (u8 *)cfg + sizeof(*cfg) + tokens_size + 10057 data_size + wake_size; 10058 memcpy((void *)cfg->wake_mask, 10059 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_MASK]), 10060 wake_mask_size); 10061 if (tok) { 10062 cfg->tokens_size = tokens_size; 10063 memcpy(&cfg->payload_tok, tok, sizeof(*tok) + tokens_size); 10064 } 10065 10066 trig->tcp = cfg; 10067 10068 return 0; 10069 } 10070 10071 static int nl80211_parse_wowlan_nd(struct cfg80211_registered_device *rdev, 10072 const struct wiphy_wowlan_support *wowlan, 10073 struct nlattr *attr, 10074 struct cfg80211_wowlan *trig) 10075 { 10076 struct nlattr **tb; 10077 int err; 10078 10079 tb = kzalloc(NUM_NL80211_ATTR * sizeof(*tb), GFP_KERNEL); 10080 if (!tb) 10081 return -ENOMEM; 10082 10083 if (!(wowlan->flags & WIPHY_WOWLAN_NET_DETECT)) { 10084 err = -EOPNOTSUPP; 10085 goto out; 10086 } 10087 10088 err = nla_parse_nested(tb, NL80211_ATTR_MAX, attr, nl80211_policy); 10089 if (err) 10090 goto out; 10091 10092 trig->nd_config = nl80211_parse_sched_scan(&rdev->wiphy, NULL, tb, 10093 wowlan->max_nd_match_sets); 10094 err = PTR_ERR_OR_ZERO(trig->nd_config); 10095 if (err) 10096 trig->nd_config = NULL; 10097 10098 out: 10099 kfree(tb); 10100 return err; 10101 } 10102 10103 static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info) 10104 { 10105 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10106 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG]; 10107 struct cfg80211_wowlan new_triggers = {}; 10108 struct cfg80211_wowlan *ntrig; 10109 const struct wiphy_wowlan_support *wowlan = rdev->wiphy.wowlan; 10110 int err, i; 10111 bool prev_enabled = rdev->wiphy.wowlan_config; 10112 bool regular = false; 10113 10114 if (!wowlan) 10115 return -EOPNOTSUPP; 10116 10117 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) { 10118 cfg80211_rdev_free_wowlan(rdev); 10119 rdev->wiphy.wowlan_config = NULL; 10120 goto set_wakeup; 10121 } 10122 10123 err = nla_parse_nested(tb, MAX_NL80211_WOWLAN_TRIG, 10124 info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS], 10125 nl80211_wowlan_policy); 10126 if (err) 10127 return err; 10128 10129 if (tb[NL80211_WOWLAN_TRIG_ANY]) { 10130 if (!(wowlan->flags & WIPHY_WOWLAN_ANY)) 10131 return -EINVAL; 10132 new_triggers.any = true; 10133 } 10134 10135 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) { 10136 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT)) 10137 return -EINVAL; 10138 new_triggers.disconnect = true; 10139 regular = true; 10140 } 10141 10142 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) { 10143 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT)) 10144 return -EINVAL; 10145 new_triggers.magic_pkt = true; 10146 regular = true; 10147 } 10148 10149 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED]) 10150 return -EINVAL; 10151 10152 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) { 10153 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE)) 10154 return -EINVAL; 10155 new_triggers.gtk_rekey_failure = true; 10156 regular = true; 10157 } 10158 10159 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) { 10160 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ)) 10161 return -EINVAL; 10162 new_triggers.eap_identity_req = true; 10163 regular = true; 10164 } 10165 10166 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) { 10167 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE)) 10168 return -EINVAL; 10169 new_triggers.four_way_handshake = true; 10170 regular = true; 10171 } 10172 10173 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) { 10174 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE)) 10175 return -EINVAL; 10176 new_triggers.rfkill_release = true; 10177 regular = true; 10178 } 10179 10180 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) { 10181 struct nlattr *pat; 10182 int n_patterns = 0; 10183 int rem, pat_len, mask_len, pkt_offset; 10184 struct nlattr *pat_tb[NUM_NL80211_PKTPAT]; 10185 10186 regular = true; 10187 10188 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN], 10189 rem) 10190 n_patterns++; 10191 if (n_patterns > wowlan->n_patterns) 10192 return -EINVAL; 10193 10194 new_triggers.patterns = kcalloc(n_patterns, 10195 sizeof(new_triggers.patterns[0]), 10196 GFP_KERNEL); 10197 if (!new_triggers.patterns) 10198 return -ENOMEM; 10199 10200 new_triggers.n_patterns = n_patterns; 10201 i = 0; 10202 10203 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN], 10204 rem) { 10205 u8 *mask_pat; 10206 10207 nla_parse_nested(pat_tb, MAX_NL80211_PKTPAT, pat, 10208 NULL); 10209 err = -EINVAL; 10210 if (!pat_tb[NL80211_PKTPAT_MASK] || 10211 !pat_tb[NL80211_PKTPAT_PATTERN]) 10212 goto error; 10213 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]); 10214 mask_len = DIV_ROUND_UP(pat_len, 8); 10215 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len) 10216 goto error; 10217 if (pat_len > wowlan->pattern_max_len || 10218 pat_len < wowlan->pattern_min_len) 10219 goto error; 10220 10221 if (!pat_tb[NL80211_PKTPAT_OFFSET]) 10222 pkt_offset = 0; 10223 else 10224 pkt_offset = nla_get_u32( 10225 pat_tb[NL80211_PKTPAT_OFFSET]); 10226 if (pkt_offset > wowlan->max_pkt_offset) 10227 goto error; 10228 new_triggers.patterns[i].pkt_offset = pkt_offset; 10229 10230 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL); 10231 if (!mask_pat) { 10232 err = -ENOMEM; 10233 goto error; 10234 } 10235 new_triggers.patterns[i].mask = mask_pat; 10236 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]), 10237 mask_len); 10238 mask_pat += mask_len; 10239 new_triggers.patterns[i].pattern = mask_pat; 10240 new_triggers.patterns[i].pattern_len = pat_len; 10241 memcpy(mask_pat, 10242 nla_data(pat_tb[NL80211_PKTPAT_PATTERN]), 10243 pat_len); 10244 i++; 10245 } 10246 } 10247 10248 if (tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION]) { 10249 regular = true; 10250 err = nl80211_parse_wowlan_tcp( 10251 rdev, tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION], 10252 &new_triggers); 10253 if (err) 10254 goto error; 10255 } 10256 10257 if (tb[NL80211_WOWLAN_TRIG_NET_DETECT]) { 10258 regular = true; 10259 err = nl80211_parse_wowlan_nd( 10260 rdev, wowlan, tb[NL80211_WOWLAN_TRIG_NET_DETECT], 10261 &new_triggers); 10262 if (err) 10263 goto error; 10264 } 10265 10266 /* The 'any' trigger means the device continues operating more or less 10267 * as in its normal operation mode and wakes up the host on most of the 10268 * normal interrupts (like packet RX, ...) 10269 * It therefore makes little sense to combine with the more constrained 10270 * wakeup trigger modes. 10271 */ 10272 if (new_triggers.any && regular) { 10273 err = -EINVAL; 10274 goto error; 10275 } 10276 10277 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL); 10278 if (!ntrig) { 10279 err = -ENOMEM; 10280 goto error; 10281 } 10282 cfg80211_rdev_free_wowlan(rdev); 10283 rdev->wiphy.wowlan_config = ntrig; 10284 10285 set_wakeup: 10286 if (rdev->ops->set_wakeup && 10287 prev_enabled != !!rdev->wiphy.wowlan_config) 10288 rdev_set_wakeup(rdev, rdev->wiphy.wowlan_config); 10289 10290 return 0; 10291 error: 10292 for (i = 0; i < new_triggers.n_patterns; i++) 10293 kfree(new_triggers.patterns[i].mask); 10294 kfree(new_triggers.patterns); 10295 if (new_triggers.tcp && new_triggers.tcp->sock) 10296 sock_release(new_triggers.tcp->sock); 10297 kfree(new_triggers.tcp); 10298 kfree(new_triggers.nd_config); 10299 return err; 10300 } 10301 #endif 10302 10303 static int nl80211_send_coalesce_rules(struct sk_buff *msg, 10304 struct cfg80211_registered_device *rdev) 10305 { 10306 struct nlattr *nl_pats, *nl_pat, *nl_rule, *nl_rules; 10307 int i, j, pat_len; 10308 struct cfg80211_coalesce_rules *rule; 10309 10310 if (!rdev->coalesce->n_rules) 10311 return 0; 10312 10313 nl_rules = nla_nest_start(msg, NL80211_ATTR_COALESCE_RULE); 10314 if (!nl_rules) 10315 return -ENOBUFS; 10316 10317 for (i = 0; i < rdev->coalesce->n_rules; i++) { 10318 nl_rule = nla_nest_start(msg, i + 1); 10319 if (!nl_rule) 10320 return -ENOBUFS; 10321 10322 rule = &rdev->coalesce->rules[i]; 10323 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_DELAY, 10324 rule->delay)) 10325 return -ENOBUFS; 10326 10327 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_CONDITION, 10328 rule->condition)) 10329 return -ENOBUFS; 10330 10331 nl_pats = nla_nest_start(msg, 10332 NL80211_ATTR_COALESCE_RULE_PKT_PATTERN); 10333 if (!nl_pats) 10334 return -ENOBUFS; 10335 10336 for (j = 0; j < rule->n_patterns; j++) { 10337 nl_pat = nla_nest_start(msg, j + 1); 10338 if (!nl_pat) 10339 return -ENOBUFS; 10340 pat_len = rule->patterns[j].pattern_len; 10341 if (nla_put(msg, NL80211_PKTPAT_MASK, 10342 DIV_ROUND_UP(pat_len, 8), 10343 rule->patterns[j].mask) || 10344 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len, 10345 rule->patterns[j].pattern) || 10346 nla_put_u32(msg, NL80211_PKTPAT_OFFSET, 10347 rule->patterns[j].pkt_offset)) 10348 return -ENOBUFS; 10349 nla_nest_end(msg, nl_pat); 10350 } 10351 nla_nest_end(msg, nl_pats); 10352 nla_nest_end(msg, nl_rule); 10353 } 10354 nla_nest_end(msg, nl_rules); 10355 10356 return 0; 10357 } 10358 10359 static int nl80211_get_coalesce(struct sk_buff *skb, struct genl_info *info) 10360 { 10361 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10362 struct sk_buff *msg; 10363 void *hdr; 10364 10365 if (!rdev->wiphy.coalesce) 10366 return -EOPNOTSUPP; 10367 10368 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 10369 if (!msg) 10370 return -ENOMEM; 10371 10372 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 10373 NL80211_CMD_GET_COALESCE); 10374 if (!hdr) 10375 goto nla_put_failure; 10376 10377 if (rdev->coalesce && nl80211_send_coalesce_rules(msg, rdev)) 10378 goto nla_put_failure; 10379 10380 genlmsg_end(msg, hdr); 10381 return genlmsg_reply(msg, info); 10382 10383 nla_put_failure: 10384 nlmsg_free(msg); 10385 return -ENOBUFS; 10386 } 10387 10388 void cfg80211_rdev_free_coalesce(struct cfg80211_registered_device *rdev) 10389 { 10390 struct cfg80211_coalesce *coalesce = rdev->coalesce; 10391 int i, j; 10392 struct cfg80211_coalesce_rules *rule; 10393 10394 if (!coalesce) 10395 return; 10396 10397 for (i = 0; i < coalesce->n_rules; i++) { 10398 rule = &coalesce->rules[i]; 10399 for (j = 0; j < rule->n_patterns; j++) 10400 kfree(rule->patterns[j].mask); 10401 kfree(rule->patterns); 10402 } 10403 kfree(coalesce->rules); 10404 kfree(coalesce); 10405 rdev->coalesce = NULL; 10406 } 10407 10408 static int nl80211_parse_coalesce_rule(struct cfg80211_registered_device *rdev, 10409 struct nlattr *rule, 10410 struct cfg80211_coalesce_rules *new_rule) 10411 { 10412 int err, i; 10413 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce; 10414 struct nlattr *tb[NUM_NL80211_ATTR_COALESCE_RULE], *pat; 10415 int rem, pat_len, mask_len, pkt_offset, n_patterns = 0; 10416 struct nlattr *pat_tb[NUM_NL80211_PKTPAT]; 10417 10418 err = nla_parse_nested(tb, NL80211_ATTR_COALESCE_RULE_MAX, rule, 10419 nl80211_coalesce_policy); 10420 if (err) 10421 return err; 10422 10423 if (tb[NL80211_ATTR_COALESCE_RULE_DELAY]) 10424 new_rule->delay = 10425 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_DELAY]); 10426 if (new_rule->delay > coalesce->max_delay) 10427 return -EINVAL; 10428 10429 if (tb[NL80211_ATTR_COALESCE_RULE_CONDITION]) 10430 new_rule->condition = 10431 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_CONDITION]); 10432 if (new_rule->condition != NL80211_COALESCE_CONDITION_MATCH && 10433 new_rule->condition != NL80211_COALESCE_CONDITION_NO_MATCH) 10434 return -EINVAL; 10435 10436 if (!tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN]) 10437 return -EINVAL; 10438 10439 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN], 10440 rem) 10441 n_patterns++; 10442 if (n_patterns > coalesce->n_patterns) 10443 return -EINVAL; 10444 10445 new_rule->patterns = kcalloc(n_patterns, sizeof(new_rule->patterns[0]), 10446 GFP_KERNEL); 10447 if (!new_rule->patterns) 10448 return -ENOMEM; 10449 10450 new_rule->n_patterns = n_patterns; 10451 i = 0; 10452 10453 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN], 10454 rem) { 10455 u8 *mask_pat; 10456 10457 nla_parse_nested(pat_tb, MAX_NL80211_PKTPAT, pat, NULL); 10458 if (!pat_tb[NL80211_PKTPAT_MASK] || 10459 !pat_tb[NL80211_PKTPAT_PATTERN]) 10460 return -EINVAL; 10461 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]); 10462 mask_len = DIV_ROUND_UP(pat_len, 8); 10463 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len) 10464 return -EINVAL; 10465 if (pat_len > coalesce->pattern_max_len || 10466 pat_len < coalesce->pattern_min_len) 10467 return -EINVAL; 10468 10469 if (!pat_tb[NL80211_PKTPAT_OFFSET]) 10470 pkt_offset = 0; 10471 else 10472 pkt_offset = nla_get_u32(pat_tb[NL80211_PKTPAT_OFFSET]); 10473 if (pkt_offset > coalesce->max_pkt_offset) 10474 return -EINVAL; 10475 new_rule->patterns[i].pkt_offset = pkt_offset; 10476 10477 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL); 10478 if (!mask_pat) 10479 return -ENOMEM; 10480 10481 new_rule->patterns[i].mask = mask_pat; 10482 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]), 10483 mask_len); 10484 10485 mask_pat += mask_len; 10486 new_rule->patterns[i].pattern = mask_pat; 10487 new_rule->patterns[i].pattern_len = pat_len; 10488 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_PATTERN]), 10489 pat_len); 10490 i++; 10491 } 10492 10493 return 0; 10494 } 10495 10496 static int nl80211_set_coalesce(struct sk_buff *skb, struct genl_info *info) 10497 { 10498 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10499 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce; 10500 struct cfg80211_coalesce new_coalesce = {}; 10501 struct cfg80211_coalesce *n_coalesce; 10502 int err, rem_rule, n_rules = 0, i, j; 10503 struct nlattr *rule; 10504 struct cfg80211_coalesce_rules *tmp_rule; 10505 10506 if (!rdev->wiphy.coalesce || !rdev->ops->set_coalesce) 10507 return -EOPNOTSUPP; 10508 10509 if (!info->attrs[NL80211_ATTR_COALESCE_RULE]) { 10510 cfg80211_rdev_free_coalesce(rdev); 10511 rdev_set_coalesce(rdev, NULL); 10512 return 0; 10513 } 10514 10515 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE], 10516 rem_rule) 10517 n_rules++; 10518 if (n_rules > coalesce->n_rules) 10519 return -EINVAL; 10520 10521 new_coalesce.rules = kcalloc(n_rules, sizeof(new_coalesce.rules[0]), 10522 GFP_KERNEL); 10523 if (!new_coalesce.rules) 10524 return -ENOMEM; 10525 10526 new_coalesce.n_rules = n_rules; 10527 i = 0; 10528 10529 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE], 10530 rem_rule) { 10531 err = nl80211_parse_coalesce_rule(rdev, rule, 10532 &new_coalesce.rules[i]); 10533 if (err) 10534 goto error; 10535 10536 i++; 10537 } 10538 10539 err = rdev_set_coalesce(rdev, &new_coalesce); 10540 if (err) 10541 goto error; 10542 10543 n_coalesce = kmemdup(&new_coalesce, sizeof(new_coalesce), GFP_KERNEL); 10544 if (!n_coalesce) { 10545 err = -ENOMEM; 10546 goto error; 10547 } 10548 cfg80211_rdev_free_coalesce(rdev); 10549 rdev->coalesce = n_coalesce; 10550 10551 return 0; 10552 error: 10553 for (i = 0; i < new_coalesce.n_rules; i++) { 10554 tmp_rule = &new_coalesce.rules[i]; 10555 for (j = 0; j < tmp_rule->n_patterns; j++) 10556 kfree(tmp_rule->patterns[j].mask); 10557 kfree(tmp_rule->patterns); 10558 } 10559 kfree(new_coalesce.rules); 10560 10561 return err; 10562 } 10563 10564 static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info) 10565 { 10566 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10567 struct net_device *dev = info->user_ptr[1]; 10568 struct wireless_dev *wdev = dev->ieee80211_ptr; 10569 struct nlattr *tb[NUM_NL80211_REKEY_DATA]; 10570 struct cfg80211_gtk_rekey_data rekey_data; 10571 int err; 10572 10573 if (!info->attrs[NL80211_ATTR_REKEY_DATA]) 10574 return -EINVAL; 10575 10576 err = nla_parse_nested(tb, MAX_NL80211_REKEY_DATA, 10577 info->attrs[NL80211_ATTR_REKEY_DATA], 10578 nl80211_rekey_policy); 10579 if (err) 10580 return err; 10581 10582 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN) 10583 return -ERANGE; 10584 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN) 10585 return -ERANGE; 10586 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN) 10587 return -ERANGE; 10588 10589 rekey_data.kek = nla_data(tb[NL80211_REKEY_DATA_KEK]); 10590 rekey_data.kck = nla_data(tb[NL80211_REKEY_DATA_KCK]); 10591 rekey_data.replay_ctr = nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]); 10592 10593 wdev_lock(wdev); 10594 if (!wdev->current_bss) { 10595 err = -ENOTCONN; 10596 goto out; 10597 } 10598 10599 if (!rdev->ops->set_rekey_data) { 10600 err = -EOPNOTSUPP; 10601 goto out; 10602 } 10603 10604 err = rdev_set_rekey_data(rdev, dev, &rekey_data); 10605 out: 10606 wdev_unlock(wdev); 10607 return err; 10608 } 10609 10610 static int nl80211_register_unexpected_frame(struct sk_buff *skb, 10611 struct genl_info *info) 10612 { 10613 struct net_device *dev = info->user_ptr[1]; 10614 struct wireless_dev *wdev = dev->ieee80211_ptr; 10615 10616 if (wdev->iftype != NL80211_IFTYPE_AP && 10617 wdev->iftype != NL80211_IFTYPE_P2P_GO) 10618 return -EINVAL; 10619 10620 if (wdev->ap_unexpected_nlportid) 10621 return -EBUSY; 10622 10623 wdev->ap_unexpected_nlportid = info->snd_portid; 10624 return 0; 10625 } 10626 10627 static int nl80211_probe_client(struct sk_buff *skb, 10628 struct genl_info *info) 10629 { 10630 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10631 struct net_device *dev = info->user_ptr[1]; 10632 struct wireless_dev *wdev = dev->ieee80211_ptr; 10633 struct sk_buff *msg; 10634 void *hdr; 10635 const u8 *addr; 10636 u64 cookie; 10637 int err; 10638 10639 if (wdev->iftype != NL80211_IFTYPE_AP && 10640 wdev->iftype != NL80211_IFTYPE_P2P_GO) 10641 return -EOPNOTSUPP; 10642 10643 if (!info->attrs[NL80211_ATTR_MAC]) 10644 return -EINVAL; 10645 10646 if (!rdev->ops->probe_client) 10647 return -EOPNOTSUPP; 10648 10649 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 10650 if (!msg) 10651 return -ENOMEM; 10652 10653 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 10654 NL80211_CMD_PROBE_CLIENT); 10655 if (!hdr) { 10656 err = -ENOBUFS; 10657 goto free_msg; 10658 } 10659 10660 addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 10661 10662 err = rdev_probe_client(rdev, dev, addr, &cookie); 10663 if (err) 10664 goto free_msg; 10665 10666 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 10667 NL80211_ATTR_PAD)) 10668 goto nla_put_failure; 10669 10670 genlmsg_end(msg, hdr); 10671 10672 return genlmsg_reply(msg, info); 10673 10674 nla_put_failure: 10675 err = -ENOBUFS; 10676 free_msg: 10677 nlmsg_free(msg); 10678 return err; 10679 } 10680 10681 static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info) 10682 { 10683 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10684 struct cfg80211_beacon_registration *reg, *nreg; 10685 int rv; 10686 10687 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS)) 10688 return -EOPNOTSUPP; 10689 10690 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL); 10691 if (!nreg) 10692 return -ENOMEM; 10693 10694 /* First, check if already registered. */ 10695 spin_lock_bh(&rdev->beacon_registrations_lock); 10696 list_for_each_entry(reg, &rdev->beacon_registrations, list) { 10697 if (reg->nlportid == info->snd_portid) { 10698 rv = -EALREADY; 10699 goto out_err; 10700 } 10701 } 10702 /* Add it to the list */ 10703 nreg->nlportid = info->snd_portid; 10704 list_add(&nreg->list, &rdev->beacon_registrations); 10705 10706 spin_unlock_bh(&rdev->beacon_registrations_lock); 10707 10708 return 0; 10709 out_err: 10710 spin_unlock_bh(&rdev->beacon_registrations_lock); 10711 kfree(nreg); 10712 return rv; 10713 } 10714 10715 static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info) 10716 { 10717 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10718 struct wireless_dev *wdev = info->user_ptr[1]; 10719 int err; 10720 10721 if (!rdev->ops->start_p2p_device) 10722 return -EOPNOTSUPP; 10723 10724 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE) 10725 return -EOPNOTSUPP; 10726 10727 if (wdev_running(wdev)) 10728 return 0; 10729 10730 if (rfkill_blocked(rdev->rfkill)) 10731 return -ERFKILL; 10732 10733 err = rdev_start_p2p_device(rdev, wdev); 10734 if (err) 10735 return err; 10736 10737 wdev->is_running = true; 10738 rdev->opencount++; 10739 10740 return 0; 10741 } 10742 10743 static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info) 10744 { 10745 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10746 struct wireless_dev *wdev = info->user_ptr[1]; 10747 10748 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE) 10749 return -EOPNOTSUPP; 10750 10751 if (!rdev->ops->stop_p2p_device) 10752 return -EOPNOTSUPP; 10753 10754 cfg80211_stop_p2p_device(rdev, wdev); 10755 10756 return 0; 10757 } 10758 10759 static int nl80211_start_nan(struct sk_buff *skb, struct genl_info *info) 10760 { 10761 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10762 struct wireless_dev *wdev = info->user_ptr[1]; 10763 struct cfg80211_nan_conf conf = {}; 10764 int err; 10765 10766 if (wdev->iftype != NL80211_IFTYPE_NAN) 10767 return -EOPNOTSUPP; 10768 10769 if (wdev_running(wdev)) 10770 return -EEXIST; 10771 10772 if (rfkill_blocked(rdev->rfkill)) 10773 return -ERFKILL; 10774 10775 if (!info->attrs[NL80211_ATTR_NAN_MASTER_PREF]) 10776 return -EINVAL; 10777 10778 conf.master_pref = 10779 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]); 10780 if (!conf.master_pref) 10781 return -EINVAL; 10782 10783 if (info->attrs[NL80211_ATTR_BANDS]) { 10784 u32 bands = nla_get_u32(info->attrs[NL80211_ATTR_BANDS]); 10785 10786 if (bands & ~(u32)wdev->wiphy->nan_supported_bands) 10787 return -EOPNOTSUPP; 10788 10789 if (bands && !(bands & BIT(NL80211_BAND_2GHZ))) 10790 return -EINVAL; 10791 10792 conf.bands = bands; 10793 } 10794 10795 err = rdev_start_nan(rdev, wdev, &conf); 10796 if (err) 10797 return err; 10798 10799 wdev->is_running = true; 10800 rdev->opencount++; 10801 10802 return 0; 10803 } 10804 10805 static int nl80211_stop_nan(struct sk_buff *skb, struct genl_info *info) 10806 { 10807 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10808 struct wireless_dev *wdev = info->user_ptr[1]; 10809 10810 if (wdev->iftype != NL80211_IFTYPE_NAN) 10811 return -EOPNOTSUPP; 10812 10813 cfg80211_stop_nan(rdev, wdev); 10814 10815 return 0; 10816 } 10817 10818 static int validate_nan_filter(struct nlattr *filter_attr) 10819 { 10820 struct nlattr *attr; 10821 int len = 0, n_entries = 0, rem; 10822 10823 nla_for_each_nested(attr, filter_attr, rem) { 10824 len += nla_len(attr); 10825 n_entries++; 10826 } 10827 10828 if (len >= U8_MAX) 10829 return -EINVAL; 10830 10831 return n_entries; 10832 } 10833 10834 static int handle_nan_filter(struct nlattr *attr_filter, 10835 struct cfg80211_nan_func *func, 10836 bool tx) 10837 { 10838 struct nlattr *attr; 10839 int n_entries, rem, i; 10840 struct cfg80211_nan_func_filter *filter; 10841 10842 n_entries = validate_nan_filter(attr_filter); 10843 if (n_entries < 0) 10844 return n_entries; 10845 10846 BUILD_BUG_ON(sizeof(*func->rx_filters) != sizeof(*func->tx_filters)); 10847 10848 filter = kcalloc(n_entries, sizeof(*func->rx_filters), GFP_KERNEL); 10849 if (!filter) 10850 return -ENOMEM; 10851 10852 i = 0; 10853 nla_for_each_nested(attr, attr_filter, rem) { 10854 filter[i].filter = nla_memdup(attr, GFP_KERNEL); 10855 filter[i].len = nla_len(attr); 10856 i++; 10857 } 10858 if (tx) { 10859 func->num_tx_filters = n_entries; 10860 func->tx_filters = filter; 10861 } else { 10862 func->num_rx_filters = n_entries; 10863 func->rx_filters = filter; 10864 } 10865 10866 return 0; 10867 } 10868 10869 static int nl80211_nan_add_func(struct sk_buff *skb, 10870 struct genl_info *info) 10871 { 10872 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10873 struct wireless_dev *wdev = info->user_ptr[1]; 10874 struct nlattr *tb[NUM_NL80211_NAN_FUNC_ATTR], *func_attr; 10875 struct cfg80211_nan_func *func; 10876 struct sk_buff *msg = NULL; 10877 void *hdr = NULL; 10878 int err = 0; 10879 10880 if (wdev->iftype != NL80211_IFTYPE_NAN) 10881 return -EOPNOTSUPP; 10882 10883 if (!wdev_running(wdev)) 10884 return -ENOTCONN; 10885 10886 if (!info->attrs[NL80211_ATTR_NAN_FUNC]) 10887 return -EINVAL; 10888 10889 if (wdev->owner_nlportid && 10890 wdev->owner_nlportid != info->snd_portid) 10891 return -ENOTCONN; 10892 10893 err = nla_parse_nested(tb, NL80211_NAN_FUNC_ATTR_MAX, 10894 info->attrs[NL80211_ATTR_NAN_FUNC], 10895 nl80211_nan_func_policy); 10896 if (err) 10897 return err; 10898 10899 func = kzalloc(sizeof(*func), GFP_KERNEL); 10900 if (!func) 10901 return -ENOMEM; 10902 10903 func->cookie = wdev->wiphy->cookie_counter++; 10904 10905 if (!tb[NL80211_NAN_FUNC_TYPE] || 10906 nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]) > NL80211_NAN_FUNC_MAX_TYPE) { 10907 err = -EINVAL; 10908 goto out; 10909 } 10910 10911 10912 func->type = nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]); 10913 10914 if (!tb[NL80211_NAN_FUNC_SERVICE_ID]) { 10915 err = -EINVAL; 10916 goto out; 10917 } 10918 10919 memcpy(func->service_id, nla_data(tb[NL80211_NAN_FUNC_SERVICE_ID]), 10920 sizeof(func->service_id)); 10921 10922 func->close_range = 10923 nla_get_flag(tb[NL80211_NAN_FUNC_CLOSE_RANGE]); 10924 10925 if (tb[NL80211_NAN_FUNC_SERVICE_INFO]) { 10926 func->serv_spec_info_len = 10927 nla_len(tb[NL80211_NAN_FUNC_SERVICE_INFO]); 10928 func->serv_spec_info = 10929 kmemdup(nla_data(tb[NL80211_NAN_FUNC_SERVICE_INFO]), 10930 func->serv_spec_info_len, 10931 GFP_KERNEL); 10932 if (!func->serv_spec_info) { 10933 err = -ENOMEM; 10934 goto out; 10935 } 10936 } 10937 10938 if (tb[NL80211_NAN_FUNC_TTL]) 10939 func->ttl = nla_get_u32(tb[NL80211_NAN_FUNC_TTL]); 10940 10941 switch (func->type) { 10942 case NL80211_NAN_FUNC_PUBLISH: 10943 if (!tb[NL80211_NAN_FUNC_PUBLISH_TYPE]) { 10944 err = -EINVAL; 10945 goto out; 10946 } 10947 10948 func->publish_type = 10949 nla_get_u8(tb[NL80211_NAN_FUNC_PUBLISH_TYPE]); 10950 func->publish_bcast = 10951 nla_get_flag(tb[NL80211_NAN_FUNC_PUBLISH_BCAST]); 10952 10953 if ((!(func->publish_type & NL80211_NAN_SOLICITED_PUBLISH)) && 10954 func->publish_bcast) { 10955 err = -EINVAL; 10956 goto out; 10957 } 10958 break; 10959 case NL80211_NAN_FUNC_SUBSCRIBE: 10960 func->subscribe_active = 10961 nla_get_flag(tb[NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE]); 10962 break; 10963 case NL80211_NAN_FUNC_FOLLOW_UP: 10964 if (!tb[NL80211_NAN_FUNC_FOLLOW_UP_ID] || 10965 !tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID]) { 10966 err = -EINVAL; 10967 goto out; 10968 } 10969 10970 func->followup_id = 10971 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_ID]); 10972 func->followup_reqid = 10973 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID]); 10974 memcpy(func->followup_dest.addr, 10975 nla_data(tb[NL80211_NAN_FUNC_FOLLOW_UP_DEST]), 10976 sizeof(func->followup_dest.addr)); 10977 if (func->ttl) { 10978 err = -EINVAL; 10979 goto out; 10980 } 10981 break; 10982 default: 10983 err = -EINVAL; 10984 goto out; 10985 } 10986 10987 if (tb[NL80211_NAN_FUNC_SRF]) { 10988 struct nlattr *srf_tb[NUM_NL80211_NAN_SRF_ATTR]; 10989 10990 err = nla_parse_nested(srf_tb, NL80211_NAN_SRF_ATTR_MAX, 10991 tb[NL80211_NAN_FUNC_SRF], 10992 nl80211_nan_srf_policy); 10993 if (err) 10994 goto out; 10995 10996 func->srf_include = 10997 nla_get_flag(srf_tb[NL80211_NAN_SRF_INCLUDE]); 10998 10999 if (srf_tb[NL80211_NAN_SRF_BF]) { 11000 if (srf_tb[NL80211_NAN_SRF_MAC_ADDRS] || 11001 !srf_tb[NL80211_NAN_SRF_BF_IDX]) { 11002 err = -EINVAL; 11003 goto out; 11004 } 11005 11006 func->srf_bf_len = 11007 nla_len(srf_tb[NL80211_NAN_SRF_BF]); 11008 func->srf_bf = 11009 kmemdup(nla_data(srf_tb[NL80211_NAN_SRF_BF]), 11010 func->srf_bf_len, GFP_KERNEL); 11011 if (!func->srf_bf) { 11012 err = -ENOMEM; 11013 goto out; 11014 } 11015 11016 func->srf_bf_idx = 11017 nla_get_u8(srf_tb[NL80211_NAN_SRF_BF_IDX]); 11018 } else { 11019 struct nlattr *attr, *mac_attr = 11020 srf_tb[NL80211_NAN_SRF_MAC_ADDRS]; 11021 int n_entries, rem, i = 0; 11022 11023 if (!mac_attr) { 11024 err = -EINVAL; 11025 goto out; 11026 } 11027 11028 n_entries = validate_acl_mac_addrs(mac_attr); 11029 if (n_entries <= 0) { 11030 err = -EINVAL; 11031 goto out; 11032 } 11033 11034 func->srf_num_macs = n_entries; 11035 func->srf_macs = 11036 kzalloc(sizeof(*func->srf_macs) * n_entries, 11037 GFP_KERNEL); 11038 if (!func->srf_macs) { 11039 err = -ENOMEM; 11040 goto out; 11041 } 11042 11043 nla_for_each_nested(attr, mac_attr, rem) 11044 memcpy(func->srf_macs[i++].addr, nla_data(attr), 11045 sizeof(*func->srf_macs)); 11046 } 11047 } 11048 11049 if (tb[NL80211_NAN_FUNC_TX_MATCH_FILTER]) { 11050 err = handle_nan_filter(tb[NL80211_NAN_FUNC_TX_MATCH_FILTER], 11051 func, true); 11052 if (err) 11053 goto out; 11054 } 11055 11056 if (tb[NL80211_NAN_FUNC_RX_MATCH_FILTER]) { 11057 err = handle_nan_filter(tb[NL80211_NAN_FUNC_RX_MATCH_FILTER], 11058 func, false); 11059 if (err) 11060 goto out; 11061 } 11062 11063 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 11064 if (!msg) { 11065 err = -ENOMEM; 11066 goto out; 11067 } 11068 11069 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 11070 NL80211_CMD_ADD_NAN_FUNCTION); 11071 /* This can't really happen - we just allocated 4KB */ 11072 if (WARN_ON(!hdr)) { 11073 err = -ENOMEM; 11074 goto out; 11075 } 11076 11077 err = rdev_add_nan_func(rdev, wdev, func); 11078 out: 11079 if (err < 0) { 11080 cfg80211_free_nan_func(func); 11081 nlmsg_free(msg); 11082 return err; 11083 } 11084 11085 /* propagate the instance id and cookie to userspace */ 11086 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, func->cookie, 11087 NL80211_ATTR_PAD)) 11088 goto nla_put_failure; 11089 11090 func_attr = nla_nest_start(msg, NL80211_ATTR_NAN_FUNC); 11091 if (!func_attr) 11092 goto nla_put_failure; 11093 11094 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, 11095 func->instance_id)) 11096 goto nla_put_failure; 11097 11098 nla_nest_end(msg, func_attr); 11099 11100 genlmsg_end(msg, hdr); 11101 return genlmsg_reply(msg, info); 11102 11103 nla_put_failure: 11104 nlmsg_free(msg); 11105 return -ENOBUFS; 11106 } 11107 11108 static int nl80211_nan_del_func(struct sk_buff *skb, 11109 struct genl_info *info) 11110 { 11111 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11112 struct wireless_dev *wdev = info->user_ptr[1]; 11113 u64 cookie; 11114 11115 if (wdev->iftype != NL80211_IFTYPE_NAN) 11116 return -EOPNOTSUPP; 11117 11118 if (!wdev_running(wdev)) 11119 return -ENOTCONN; 11120 11121 if (!info->attrs[NL80211_ATTR_COOKIE]) 11122 return -EINVAL; 11123 11124 if (wdev->owner_nlportid && 11125 wdev->owner_nlportid != info->snd_portid) 11126 return -ENOTCONN; 11127 11128 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]); 11129 11130 rdev_del_nan_func(rdev, wdev, cookie); 11131 11132 return 0; 11133 } 11134 11135 static int nl80211_nan_change_config(struct sk_buff *skb, 11136 struct genl_info *info) 11137 { 11138 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11139 struct wireless_dev *wdev = info->user_ptr[1]; 11140 struct cfg80211_nan_conf conf = {}; 11141 u32 changed = 0; 11142 11143 if (wdev->iftype != NL80211_IFTYPE_NAN) 11144 return -EOPNOTSUPP; 11145 11146 if (!wdev_running(wdev)) 11147 return -ENOTCONN; 11148 11149 if (info->attrs[NL80211_ATTR_NAN_MASTER_PREF]) { 11150 conf.master_pref = 11151 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]); 11152 if (conf.master_pref <= 1 || conf.master_pref == 255) 11153 return -EINVAL; 11154 11155 changed |= CFG80211_NAN_CONF_CHANGED_PREF; 11156 } 11157 11158 if (info->attrs[NL80211_ATTR_BANDS]) { 11159 u32 bands = nla_get_u32(info->attrs[NL80211_ATTR_BANDS]); 11160 11161 if (bands & ~(u32)wdev->wiphy->nan_supported_bands) 11162 return -EOPNOTSUPP; 11163 11164 if (bands && !(bands & BIT(NL80211_BAND_2GHZ))) 11165 return -EINVAL; 11166 11167 conf.bands = bands; 11168 changed |= CFG80211_NAN_CONF_CHANGED_BANDS; 11169 } 11170 11171 if (!changed) 11172 return -EINVAL; 11173 11174 return rdev_nan_change_conf(rdev, wdev, &conf, changed); 11175 } 11176 11177 void cfg80211_nan_match(struct wireless_dev *wdev, 11178 struct cfg80211_nan_match_params *match, gfp_t gfp) 11179 { 11180 struct wiphy *wiphy = wdev->wiphy; 11181 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 11182 struct nlattr *match_attr, *local_func_attr, *peer_func_attr; 11183 struct sk_buff *msg; 11184 void *hdr; 11185 11186 if (WARN_ON(!match->inst_id || !match->peer_inst_id || !match->addr)) 11187 return; 11188 11189 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 11190 if (!msg) 11191 return; 11192 11193 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NAN_MATCH); 11194 if (!hdr) { 11195 nlmsg_free(msg); 11196 return; 11197 } 11198 11199 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 11200 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 11201 wdev->netdev->ifindex)) || 11202 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 11203 NL80211_ATTR_PAD)) 11204 goto nla_put_failure; 11205 11206 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, match->cookie, 11207 NL80211_ATTR_PAD) || 11208 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, match->addr)) 11209 goto nla_put_failure; 11210 11211 match_attr = nla_nest_start(msg, NL80211_ATTR_NAN_MATCH); 11212 if (!match_attr) 11213 goto nla_put_failure; 11214 11215 local_func_attr = nla_nest_start(msg, NL80211_NAN_MATCH_FUNC_LOCAL); 11216 if (!local_func_attr) 11217 goto nla_put_failure; 11218 11219 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->inst_id)) 11220 goto nla_put_failure; 11221 11222 nla_nest_end(msg, local_func_attr); 11223 11224 peer_func_attr = nla_nest_start(msg, NL80211_NAN_MATCH_FUNC_PEER); 11225 if (!peer_func_attr) 11226 goto nla_put_failure; 11227 11228 if (nla_put_u8(msg, NL80211_NAN_FUNC_TYPE, match->type) || 11229 nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->peer_inst_id)) 11230 goto nla_put_failure; 11231 11232 if (match->info && match->info_len && 11233 nla_put(msg, NL80211_NAN_FUNC_SERVICE_INFO, match->info_len, 11234 match->info)) 11235 goto nla_put_failure; 11236 11237 nla_nest_end(msg, peer_func_attr); 11238 nla_nest_end(msg, match_attr); 11239 genlmsg_end(msg, hdr); 11240 11241 if (!wdev->owner_nlportid) 11242 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), 11243 msg, 0, NL80211_MCGRP_NAN, gfp); 11244 else 11245 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, 11246 wdev->owner_nlportid); 11247 11248 return; 11249 11250 nla_put_failure: 11251 nlmsg_free(msg); 11252 } 11253 EXPORT_SYMBOL(cfg80211_nan_match); 11254 11255 void cfg80211_nan_func_terminated(struct wireless_dev *wdev, 11256 u8 inst_id, 11257 enum nl80211_nan_func_term_reason reason, 11258 u64 cookie, gfp_t gfp) 11259 { 11260 struct wiphy *wiphy = wdev->wiphy; 11261 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 11262 struct sk_buff *msg; 11263 struct nlattr *func_attr; 11264 void *hdr; 11265 11266 if (WARN_ON(!inst_id)) 11267 return; 11268 11269 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 11270 if (!msg) 11271 return; 11272 11273 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_NAN_FUNCTION); 11274 if (!hdr) { 11275 nlmsg_free(msg); 11276 return; 11277 } 11278 11279 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 11280 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 11281 wdev->netdev->ifindex)) || 11282 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 11283 NL80211_ATTR_PAD)) 11284 goto nla_put_failure; 11285 11286 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 11287 NL80211_ATTR_PAD)) 11288 goto nla_put_failure; 11289 11290 func_attr = nla_nest_start(msg, NL80211_ATTR_NAN_FUNC); 11291 if (!func_attr) 11292 goto nla_put_failure; 11293 11294 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, inst_id) || 11295 nla_put_u8(msg, NL80211_NAN_FUNC_TERM_REASON, reason)) 11296 goto nla_put_failure; 11297 11298 nla_nest_end(msg, func_attr); 11299 genlmsg_end(msg, hdr); 11300 11301 if (!wdev->owner_nlportid) 11302 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), 11303 msg, 0, NL80211_MCGRP_NAN, gfp); 11304 else 11305 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, 11306 wdev->owner_nlportid); 11307 11308 return; 11309 11310 nla_put_failure: 11311 nlmsg_free(msg); 11312 } 11313 EXPORT_SYMBOL(cfg80211_nan_func_terminated); 11314 11315 static int nl80211_get_protocol_features(struct sk_buff *skb, 11316 struct genl_info *info) 11317 { 11318 void *hdr; 11319 struct sk_buff *msg; 11320 11321 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 11322 if (!msg) 11323 return -ENOMEM; 11324 11325 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 11326 NL80211_CMD_GET_PROTOCOL_FEATURES); 11327 if (!hdr) 11328 goto nla_put_failure; 11329 11330 if (nla_put_u32(msg, NL80211_ATTR_PROTOCOL_FEATURES, 11331 NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP)) 11332 goto nla_put_failure; 11333 11334 genlmsg_end(msg, hdr); 11335 return genlmsg_reply(msg, info); 11336 11337 nla_put_failure: 11338 kfree_skb(msg); 11339 return -ENOBUFS; 11340 } 11341 11342 static int nl80211_update_ft_ies(struct sk_buff *skb, struct genl_info *info) 11343 { 11344 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11345 struct cfg80211_update_ft_ies_params ft_params; 11346 struct net_device *dev = info->user_ptr[1]; 11347 11348 if (!rdev->ops->update_ft_ies) 11349 return -EOPNOTSUPP; 11350 11351 if (!info->attrs[NL80211_ATTR_MDID] || 11352 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 11353 return -EINVAL; 11354 11355 memset(&ft_params, 0, sizeof(ft_params)); 11356 ft_params.md = nla_get_u16(info->attrs[NL80211_ATTR_MDID]); 11357 ft_params.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 11358 ft_params.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 11359 11360 return rdev_update_ft_ies(rdev, dev, &ft_params); 11361 } 11362 11363 static int nl80211_crit_protocol_start(struct sk_buff *skb, 11364 struct genl_info *info) 11365 { 11366 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11367 struct wireless_dev *wdev = info->user_ptr[1]; 11368 enum nl80211_crit_proto_id proto = NL80211_CRIT_PROTO_UNSPEC; 11369 u16 duration; 11370 int ret; 11371 11372 if (!rdev->ops->crit_proto_start) 11373 return -EOPNOTSUPP; 11374 11375 if (WARN_ON(!rdev->ops->crit_proto_stop)) 11376 return -EINVAL; 11377 11378 if (rdev->crit_proto_nlportid) 11379 return -EBUSY; 11380 11381 /* determine protocol if provided */ 11382 if (info->attrs[NL80211_ATTR_CRIT_PROT_ID]) 11383 proto = nla_get_u16(info->attrs[NL80211_ATTR_CRIT_PROT_ID]); 11384 11385 if (proto >= NUM_NL80211_CRIT_PROTO) 11386 return -EINVAL; 11387 11388 /* timeout must be provided */ 11389 if (!info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]) 11390 return -EINVAL; 11391 11392 duration = 11393 nla_get_u16(info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]); 11394 11395 if (duration > NL80211_CRIT_PROTO_MAX_DURATION) 11396 return -ERANGE; 11397 11398 ret = rdev_crit_proto_start(rdev, wdev, proto, duration); 11399 if (!ret) 11400 rdev->crit_proto_nlportid = info->snd_portid; 11401 11402 return ret; 11403 } 11404 11405 static int nl80211_crit_protocol_stop(struct sk_buff *skb, 11406 struct genl_info *info) 11407 { 11408 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11409 struct wireless_dev *wdev = info->user_ptr[1]; 11410 11411 if (!rdev->ops->crit_proto_stop) 11412 return -EOPNOTSUPP; 11413 11414 if (rdev->crit_proto_nlportid) { 11415 rdev->crit_proto_nlportid = 0; 11416 rdev_crit_proto_stop(rdev, wdev); 11417 } 11418 return 0; 11419 } 11420 11421 static int nl80211_vendor_cmd(struct sk_buff *skb, struct genl_info *info) 11422 { 11423 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11424 struct wireless_dev *wdev = 11425 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs); 11426 int i, err; 11427 u32 vid, subcmd; 11428 11429 if (!rdev->wiphy.vendor_commands) 11430 return -EOPNOTSUPP; 11431 11432 if (IS_ERR(wdev)) { 11433 err = PTR_ERR(wdev); 11434 if (err != -EINVAL) 11435 return err; 11436 wdev = NULL; 11437 } else if (wdev->wiphy != &rdev->wiphy) { 11438 return -EINVAL; 11439 } 11440 11441 if (!info->attrs[NL80211_ATTR_VENDOR_ID] || 11442 !info->attrs[NL80211_ATTR_VENDOR_SUBCMD]) 11443 return -EINVAL; 11444 11445 vid = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_ID]); 11446 subcmd = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_SUBCMD]); 11447 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) { 11448 const struct wiphy_vendor_command *vcmd; 11449 void *data = NULL; 11450 int len = 0; 11451 11452 vcmd = &rdev->wiphy.vendor_commands[i]; 11453 11454 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd) 11455 continue; 11456 11457 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV | 11458 WIPHY_VENDOR_CMD_NEED_NETDEV)) { 11459 if (!wdev) 11460 return -EINVAL; 11461 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV && 11462 !wdev->netdev) 11463 return -EINVAL; 11464 11465 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) { 11466 if (!wdev_running(wdev)) 11467 return -ENETDOWN; 11468 } 11469 11470 if (!vcmd->doit) 11471 return -EOPNOTSUPP; 11472 } else { 11473 wdev = NULL; 11474 } 11475 11476 if (info->attrs[NL80211_ATTR_VENDOR_DATA]) { 11477 data = nla_data(info->attrs[NL80211_ATTR_VENDOR_DATA]); 11478 len = nla_len(info->attrs[NL80211_ATTR_VENDOR_DATA]); 11479 } 11480 11481 rdev->cur_cmd_info = info; 11482 err = rdev->wiphy.vendor_commands[i].doit(&rdev->wiphy, wdev, 11483 data, len); 11484 rdev->cur_cmd_info = NULL; 11485 return err; 11486 } 11487 11488 return -EOPNOTSUPP; 11489 } 11490 11491 static int nl80211_prepare_vendor_dump(struct sk_buff *skb, 11492 struct netlink_callback *cb, 11493 struct cfg80211_registered_device **rdev, 11494 struct wireless_dev **wdev) 11495 { 11496 struct nlattr **attrbuf = genl_family_attrbuf(&nl80211_fam); 11497 u32 vid, subcmd; 11498 unsigned int i; 11499 int vcmd_idx = -1; 11500 int err; 11501 void *data = NULL; 11502 unsigned int data_len = 0; 11503 11504 if (cb->args[0]) { 11505 /* subtract the 1 again here */ 11506 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1); 11507 struct wireless_dev *tmp; 11508 11509 if (!wiphy) 11510 return -ENODEV; 11511 *rdev = wiphy_to_rdev(wiphy); 11512 *wdev = NULL; 11513 11514 if (cb->args[1]) { 11515 list_for_each_entry(tmp, &wiphy->wdev_list, list) { 11516 if (tmp->identifier == cb->args[1] - 1) { 11517 *wdev = tmp; 11518 break; 11519 } 11520 } 11521 } 11522 11523 /* keep rtnl locked in successful case */ 11524 return 0; 11525 } 11526 11527 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, 11528 attrbuf, nl80211_fam.maxattr, nl80211_policy); 11529 if (err) 11530 return err; 11531 11532 if (!attrbuf[NL80211_ATTR_VENDOR_ID] || 11533 !attrbuf[NL80211_ATTR_VENDOR_SUBCMD]) 11534 return -EINVAL; 11535 11536 *wdev = __cfg80211_wdev_from_attrs(sock_net(skb->sk), attrbuf); 11537 if (IS_ERR(*wdev)) 11538 *wdev = NULL; 11539 11540 *rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf); 11541 if (IS_ERR(*rdev)) 11542 return PTR_ERR(*rdev); 11543 11544 vid = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_ID]); 11545 subcmd = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_SUBCMD]); 11546 11547 for (i = 0; i < (*rdev)->wiphy.n_vendor_commands; i++) { 11548 const struct wiphy_vendor_command *vcmd; 11549 11550 vcmd = &(*rdev)->wiphy.vendor_commands[i]; 11551 11552 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd) 11553 continue; 11554 11555 if (!vcmd->dumpit) 11556 return -EOPNOTSUPP; 11557 11558 vcmd_idx = i; 11559 break; 11560 } 11561 11562 if (vcmd_idx < 0) 11563 return -EOPNOTSUPP; 11564 11565 if (attrbuf[NL80211_ATTR_VENDOR_DATA]) { 11566 data = nla_data(attrbuf[NL80211_ATTR_VENDOR_DATA]); 11567 data_len = nla_len(attrbuf[NL80211_ATTR_VENDOR_DATA]); 11568 } 11569 11570 /* 0 is the first index - add 1 to parse only once */ 11571 cb->args[0] = (*rdev)->wiphy_idx + 1; 11572 /* add 1 to know if it was NULL */ 11573 cb->args[1] = *wdev ? (*wdev)->identifier + 1 : 0; 11574 cb->args[2] = vcmd_idx; 11575 cb->args[3] = (unsigned long)data; 11576 cb->args[4] = data_len; 11577 11578 /* keep rtnl locked in successful case */ 11579 return 0; 11580 } 11581 11582 static int nl80211_vendor_cmd_dump(struct sk_buff *skb, 11583 struct netlink_callback *cb) 11584 { 11585 struct cfg80211_registered_device *rdev; 11586 struct wireless_dev *wdev; 11587 unsigned int vcmd_idx; 11588 const struct wiphy_vendor_command *vcmd; 11589 void *data; 11590 int data_len; 11591 int err; 11592 struct nlattr *vendor_data; 11593 11594 rtnl_lock(); 11595 err = nl80211_prepare_vendor_dump(skb, cb, &rdev, &wdev); 11596 if (err) 11597 goto out; 11598 11599 vcmd_idx = cb->args[2]; 11600 data = (void *)cb->args[3]; 11601 data_len = cb->args[4]; 11602 vcmd = &rdev->wiphy.vendor_commands[vcmd_idx]; 11603 11604 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV | 11605 WIPHY_VENDOR_CMD_NEED_NETDEV)) { 11606 if (!wdev) { 11607 err = -EINVAL; 11608 goto out; 11609 } 11610 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV && 11611 !wdev->netdev) { 11612 err = -EINVAL; 11613 goto out; 11614 } 11615 11616 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) { 11617 if (!wdev_running(wdev)) { 11618 err = -ENETDOWN; 11619 goto out; 11620 } 11621 } 11622 } 11623 11624 while (1) { 11625 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid, 11626 cb->nlh->nlmsg_seq, NLM_F_MULTI, 11627 NL80211_CMD_VENDOR); 11628 if (!hdr) 11629 break; 11630 11631 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 11632 (wdev && nla_put_u64_64bit(skb, NL80211_ATTR_WDEV, 11633 wdev_id(wdev), 11634 NL80211_ATTR_PAD))) { 11635 genlmsg_cancel(skb, hdr); 11636 break; 11637 } 11638 11639 vendor_data = nla_nest_start(skb, NL80211_ATTR_VENDOR_DATA); 11640 if (!vendor_data) { 11641 genlmsg_cancel(skb, hdr); 11642 break; 11643 } 11644 11645 err = vcmd->dumpit(&rdev->wiphy, wdev, skb, data, data_len, 11646 (unsigned long *)&cb->args[5]); 11647 nla_nest_end(skb, vendor_data); 11648 11649 if (err == -ENOBUFS || err == -ENOENT) { 11650 genlmsg_cancel(skb, hdr); 11651 break; 11652 } else if (err) { 11653 genlmsg_cancel(skb, hdr); 11654 goto out; 11655 } 11656 11657 genlmsg_end(skb, hdr); 11658 } 11659 11660 err = skb->len; 11661 out: 11662 rtnl_unlock(); 11663 return err; 11664 } 11665 11666 struct sk_buff *__cfg80211_alloc_reply_skb(struct wiphy *wiphy, 11667 enum nl80211_commands cmd, 11668 enum nl80211_attrs attr, 11669 int approxlen) 11670 { 11671 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 11672 11673 if (WARN_ON(!rdev->cur_cmd_info)) 11674 return NULL; 11675 11676 return __cfg80211_alloc_vendor_skb(rdev, NULL, approxlen, 11677 rdev->cur_cmd_info->snd_portid, 11678 rdev->cur_cmd_info->snd_seq, 11679 cmd, attr, NULL, GFP_KERNEL); 11680 } 11681 EXPORT_SYMBOL(__cfg80211_alloc_reply_skb); 11682 11683 int cfg80211_vendor_cmd_reply(struct sk_buff *skb) 11684 { 11685 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0]; 11686 void *hdr = ((void **)skb->cb)[1]; 11687 struct nlattr *data = ((void **)skb->cb)[2]; 11688 11689 /* clear CB data for netlink core to own from now on */ 11690 memset(skb->cb, 0, sizeof(skb->cb)); 11691 11692 if (WARN_ON(!rdev->cur_cmd_info)) { 11693 kfree_skb(skb); 11694 return -EINVAL; 11695 } 11696 11697 nla_nest_end(skb, data); 11698 genlmsg_end(skb, hdr); 11699 return genlmsg_reply(skb, rdev->cur_cmd_info); 11700 } 11701 EXPORT_SYMBOL_GPL(cfg80211_vendor_cmd_reply); 11702 11703 static int nl80211_set_qos_map(struct sk_buff *skb, 11704 struct genl_info *info) 11705 { 11706 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11707 struct cfg80211_qos_map *qos_map = NULL; 11708 struct net_device *dev = info->user_ptr[1]; 11709 u8 *pos, len, num_des, des_len, des; 11710 int ret; 11711 11712 if (!rdev->ops->set_qos_map) 11713 return -EOPNOTSUPP; 11714 11715 if (info->attrs[NL80211_ATTR_QOS_MAP]) { 11716 pos = nla_data(info->attrs[NL80211_ATTR_QOS_MAP]); 11717 len = nla_len(info->attrs[NL80211_ATTR_QOS_MAP]); 11718 11719 if (len % 2 || len < IEEE80211_QOS_MAP_LEN_MIN || 11720 len > IEEE80211_QOS_MAP_LEN_MAX) 11721 return -EINVAL; 11722 11723 qos_map = kzalloc(sizeof(struct cfg80211_qos_map), GFP_KERNEL); 11724 if (!qos_map) 11725 return -ENOMEM; 11726 11727 num_des = (len - IEEE80211_QOS_MAP_LEN_MIN) >> 1; 11728 if (num_des) { 11729 des_len = num_des * 11730 sizeof(struct cfg80211_dscp_exception); 11731 memcpy(qos_map->dscp_exception, pos, des_len); 11732 qos_map->num_des = num_des; 11733 for (des = 0; des < num_des; des++) { 11734 if (qos_map->dscp_exception[des].up > 7) { 11735 kfree(qos_map); 11736 return -EINVAL; 11737 } 11738 } 11739 pos += des_len; 11740 } 11741 memcpy(qos_map->up, pos, IEEE80211_QOS_MAP_LEN_MIN); 11742 } 11743 11744 wdev_lock(dev->ieee80211_ptr); 11745 ret = nl80211_key_allowed(dev->ieee80211_ptr); 11746 if (!ret) 11747 ret = rdev_set_qos_map(rdev, dev, qos_map); 11748 wdev_unlock(dev->ieee80211_ptr); 11749 11750 kfree(qos_map); 11751 return ret; 11752 } 11753 11754 static int nl80211_add_tx_ts(struct sk_buff *skb, struct genl_info *info) 11755 { 11756 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11757 struct net_device *dev = info->user_ptr[1]; 11758 struct wireless_dev *wdev = dev->ieee80211_ptr; 11759 const u8 *peer; 11760 u8 tsid, up; 11761 u16 admitted_time = 0; 11762 int err; 11763 11764 if (!(rdev->wiphy.features & NL80211_FEATURE_SUPPORTS_WMM_ADMISSION)) 11765 return -EOPNOTSUPP; 11766 11767 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC] || 11768 !info->attrs[NL80211_ATTR_USER_PRIO]) 11769 return -EINVAL; 11770 11771 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]); 11772 if (tsid >= IEEE80211_NUM_TIDS) 11773 return -EINVAL; 11774 11775 up = nla_get_u8(info->attrs[NL80211_ATTR_USER_PRIO]); 11776 if (up >= IEEE80211_NUM_UPS) 11777 return -EINVAL; 11778 11779 /* WMM uses TIDs 0-7 even for TSPEC */ 11780 if (tsid >= IEEE80211_FIRST_TSPEC_TSID) { 11781 /* TODO: handle 802.11 TSPEC/admission control 11782 * need more attributes for that (e.g. BA session requirement); 11783 * change the WMM adminssion test above to allow both then 11784 */ 11785 return -EINVAL; 11786 } 11787 11788 peer = nla_data(info->attrs[NL80211_ATTR_MAC]); 11789 11790 if (info->attrs[NL80211_ATTR_ADMITTED_TIME]) { 11791 admitted_time = 11792 nla_get_u16(info->attrs[NL80211_ATTR_ADMITTED_TIME]); 11793 if (!admitted_time) 11794 return -EINVAL; 11795 } 11796 11797 wdev_lock(wdev); 11798 switch (wdev->iftype) { 11799 case NL80211_IFTYPE_STATION: 11800 case NL80211_IFTYPE_P2P_CLIENT: 11801 if (wdev->current_bss) 11802 break; 11803 err = -ENOTCONN; 11804 goto out; 11805 default: 11806 err = -EOPNOTSUPP; 11807 goto out; 11808 } 11809 11810 err = rdev_add_tx_ts(rdev, dev, tsid, peer, up, admitted_time); 11811 11812 out: 11813 wdev_unlock(wdev); 11814 return err; 11815 } 11816 11817 static int nl80211_del_tx_ts(struct sk_buff *skb, struct genl_info *info) 11818 { 11819 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11820 struct net_device *dev = info->user_ptr[1]; 11821 struct wireless_dev *wdev = dev->ieee80211_ptr; 11822 const u8 *peer; 11823 u8 tsid; 11824 int err; 11825 11826 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC]) 11827 return -EINVAL; 11828 11829 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]); 11830 peer = nla_data(info->attrs[NL80211_ATTR_MAC]); 11831 11832 wdev_lock(wdev); 11833 err = rdev_del_tx_ts(rdev, dev, tsid, peer); 11834 wdev_unlock(wdev); 11835 11836 return err; 11837 } 11838 11839 static int nl80211_tdls_channel_switch(struct sk_buff *skb, 11840 struct genl_info *info) 11841 { 11842 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11843 struct net_device *dev = info->user_ptr[1]; 11844 struct wireless_dev *wdev = dev->ieee80211_ptr; 11845 struct cfg80211_chan_def chandef = {}; 11846 const u8 *addr; 11847 u8 oper_class; 11848 int err; 11849 11850 if (!rdev->ops->tdls_channel_switch || 11851 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH)) 11852 return -EOPNOTSUPP; 11853 11854 switch (dev->ieee80211_ptr->iftype) { 11855 case NL80211_IFTYPE_STATION: 11856 case NL80211_IFTYPE_P2P_CLIENT: 11857 break; 11858 default: 11859 return -EOPNOTSUPP; 11860 } 11861 11862 if (!info->attrs[NL80211_ATTR_MAC] || 11863 !info->attrs[NL80211_ATTR_OPER_CLASS]) 11864 return -EINVAL; 11865 11866 err = nl80211_parse_chandef(rdev, info, &chandef); 11867 if (err) 11868 return err; 11869 11870 /* 11871 * Don't allow wide channels on the 2.4Ghz band, as per IEEE802.11-2012 11872 * section 10.22.6.2.1. Disallow 5/10Mhz channels as well for now, the 11873 * specification is not defined for them. 11874 */ 11875 if (chandef.chan->band == NL80211_BAND_2GHZ && 11876 chandef.width != NL80211_CHAN_WIDTH_20_NOHT && 11877 chandef.width != NL80211_CHAN_WIDTH_20) 11878 return -EINVAL; 11879 11880 /* we will be active on the TDLS link */ 11881 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef, 11882 wdev->iftype)) 11883 return -EINVAL; 11884 11885 /* don't allow switching to DFS channels */ 11886 if (cfg80211_chandef_dfs_required(wdev->wiphy, &chandef, wdev->iftype)) 11887 return -EINVAL; 11888 11889 addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 11890 oper_class = nla_get_u8(info->attrs[NL80211_ATTR_OPER_CLASS]); 11891 11892 wdev_lock(wdev); 11893 err = rdev_tdls_channel_switch(rdev, dev, addr, oper_class, &chandef); 11894 wdev_unlock(wdev); 11895 11896 return err; 11897 } 11898 11899 static int nl80211_tdls_cancel_channel_switch(struct sk_buff *skb, 11900 struct genl_info *info) 11901 { 11902 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11903 struct net_device *dev = info->user_ptr[1]; 11904 struct wireless_dev *wdev = dev->ieee80211_ptr; 11905 const u8 *addr; 11906 11907 if (!rdev->ops->tdls_channel_switch || 11908 !rdev->ops->tdls_cancel_channel_switch || 11909 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH)) 11910 return -EOPNOTSUPP; 11911 11912 switch (dev->ieee80211_ptr->iftype) { 11913 case NL80211_IFTYPE_STATION: 11914 case NL80211_IFTYPE_P2P_CLIENT: 11915 break; 11916 default: 11917 return -EOPNOTSUPP; 11918 } 11919 11920 if (!info->attrs[NL80211_ATTR_MAC]) 11921 return -EINVAL; 11922 11923 addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 11924 11925 wdev_lock(wdev); 11926 rdev_tdls_cancel_channel_switch(rdev, dev, addr); 11927 wdev_unlock(wdev); 11928 11929 return 0; 11930 } 11931 11932 static int nl80211_set_multicast_to_unicast(struct sk_buff *skb, 11933 struct genl_info *info) 11934 { 11935 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11936 struct net_device *dev = info->user_ptr[1]; 11937 struct wireless_dev *wdev = dev->ieee80211_ptr; 11938 const struct nlattr *nla; 11939 bool enabled; 11940 11941 if (!rdev->ops->set_multicast_to_unicast) 11942 return -EOPNOTSUPP; 11943 11944 if (wdev->iftype != NL80211_IFTYPE_AP && 11945 wdev->iftype != NL80211_IFTYPE_P2P_GO) 11946 return -EOPNOTSUPP; 11947 11948 nla = info->attrs[NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED]; 11949 enabled = nla_get_flag(nla); 11950 11951 return rdev_set_multicast_to_unicast(rdev, dev, enabled); 11952 } 11953 11954 #define NL80211_FLAG_NEED_WIPHY 0x01 11955 #define NL80211_FLAG_NEED_NETDEV 0x02 11956 #define NL80211_FLAG_NEED_RTNL 0x04 11957 #define NL80211_FLAG_CHECK_NETDEV_UP 0x08 11958 #define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\ 11959 NL80211_FLAG_CHECK_NETDEV_UP) 11960 #define NL80211_FLAG_NEED_WDEV 0x10 11961 /* If a netdev is associated, it must be UP, P2P must be started */ 11962 #define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\ 11963 NL80211_FLAG_CHECK_NETDEV_UP) 11964 #define NL80211_FLAG_CLEAR_SKB 0x20 11965 11966 static int nl80211_pre_doit(const struct genl_ops *ops, struct sk_buff *skb, 11967 struct genl_info *info) 11968 { 11969 struct cfg80211_registered_device *rdev; 11970 struct wireless_dev *wdev; 11971 struct net_device *dev; 11972 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL; 11973 11974 if (rtnl) 11975 rtnl_lock(); 11976 11977 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) { 11978 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info); 11979 if (IS_ERR(rdev)) { 11980 if (rtnl) 11981 rtnl_unlock(); 11982 return PTR_ERR(rdev); 11983 } 11984 info->user_ptr[0] = rdev; 11985 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV || 11986 ops->internal_flags & NL80211_FLAG_NEED_WDEV) { 11987 ASSERT_RTNL(); 11988 11989 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info), 11990 info->attrs); 11991 if (IS_ERR(wdev)) { 11992 if (rtnl) 11993 rtnl_unlock(); 11994 return PTR_ERR(wdev); 11995 } 11996 11997 dev = wdev->netdev; 11998 rdev = wiphy_to_rdev(wdev->wiphy); 11999 12000 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) { 12001 if (!dev) { 12002 if (rtnl) 12003 rtnl_unlock(); 12004 return -EINVAL; 12005 } 12006 12007 info->user_ptr[1] = dev; 12008 } else { 12009 info->user_ptr[1] = wdev; 12010 } 12011 12012 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP && 12013 !wdev_running(wdev)) { 12014 if (rtnl) 12015 rtnl_unlock(); 12016 return -ENETDOWN; 12017 } 12018 12019 if (dev) 12020 dev_hold(dev); 12021 12022 info->user_ptr[0] = rdev; 12023 } 12024 12025 return 0; 12026 } 12027 12028 static void nl80211_post_doit(const struct genl_ops *ops, struct sk_buff *skb, 12029 struct genl_info *info) 12030 { 12031 if (info->user_ptr[1]) { 12032 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) { 12033 struct wireless_dev *wdev = info->user_ptr[1]; 12034 12035 if (wdev->netdev) 12036 dev_put(wdev->netdev); 12037 } else { 12038 dev_put(info->user_ptr[1]); 12039 } 12040 } 12041 12042 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL) 12043 rtnl_unlock(); 12044 12045 /* If needed, clear the netlink message payload from the SKB 12046 * as it might contain key data that shouldn't stick around on 12047 * the heap after the SKB is freed. The netlink message header 12048 * is still needed for further processing, so leave it intact. 12049 */ 12050 if (ops->internal_flags & NL80211_FLAG_CLEAR_SKB) { 12051 struct nlmsghdr *nlh = nlmsg_hdr(skb); 12052 12053 memset(nlmsg_data(nlh), 0, nlmsg_len(nlh)); 12054 } 12055 } 12056 12057 static const struct genl_ops nl80211_ops[] = { 12058 { 12059 .cmd = NL80211_CMD_GET_WIPHY, 12060 .doit = nl80211_get_wiphy, 12061 .dumpit = nl80211_dump_wiphy, 12062 .done = nl80211_dump_wiphy_done, 12063 .policy = nl80211_policy, 12064 /* can be retrieved by unprivileged users */ 12065 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12066 NL80211_FLAG_NEED_RTNL, 12067 }, 12068 { 12069 .cmd = NL80211_CMD_SET_WIPHY, 12070 .doit = nl80211_set_wiphy, 12071 .policy = nl80211_policy, 12072 .flags = GENL_UNS_ADMIN_PERM, 12073 .internal_flags = NL80211_FLAG_NEED_RTNL, 12074 }, 12075 { 12076 .cmd = NL80211_CMD_GET_INTERFACE, 12077 .doit = nl80211_get_interface, 12078 .dumpit = nl80211_dump_interface, 12079 .policy = nl80211_policy, 12080 /* can be retrieved by unprivileged users */ 12081 .internal_flags = NL80211_FLAG_NEED_WDEV | 12082 NL80211_FLAG_NEED_RTNL, 12083 }, 12084 { 12085 .cmd = NL80211_CMD_SET_INTERFACE, 12086 .doit = nl80211_set_interface, 12087 .policy = nl80211_policy, 12088 .flags = GENL_UNS_ADMIN_PERM, 12089 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12090 NL80211_FLAG_NEED_RTNL, 12091 }, 12092 { 12093 .cmd = NL80211_CMD_NEW_INTERFACE, 12094 .doit = nl80211_new_interface, 12095 .policy = nl80211_policy, 12096 .flags = GENL_UNS_ADMIN_PERM, 12097 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12098 NL80211_FLAG_NEED_RTNL, 12099 }, 12100 { 12101 .cmd = NL80211_CMD_DEL_INTERFACE, 12102 .doit = nl80211_del_interface, 12103 .policy = nl80211_policy, 12104 .flags = GENL_UNS_ADMIN_PERM, 12105 .internal_flags = NL80211_FLAG_NEED_WDEV | 12106 NL80211_FLAG_NEED_RTNL, 12107 }, 12108 { 12109 .cmd = NL80211_CMD_GET_KEY, 12110 .doit = nl80211_get_key, 12111 .policy = nl80211_policy, 12112 .flags = GENL_UNS_ADMIN_PERM, 12113 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12114 NL80211_FLAG_NEED_RTNL, 12115 }, 12116 { 12117 .cmd = NL80211_CMD_SET_KEY, 12118 .doit = nl80211_set_key, 12119 .policy = nl80211_policy, 12120 .flags = GENL_UNS_ADMIN_PERM, 12121 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12122 NL80211_FLAG_NEED_RTNL | 12123 NL80211_FLAG_CLEAR_SKB, 12124 }, 12125 { 12126 .cmd = NL80211_CMD_NEW_KEY, 12127 .doit = nl80211_new_key, 12128 .policy = nl80211_policy, 12129 .flags = GENL_UNS_ADMIN_PERM, 12130 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12131 NL80211_FLAG_NEED_RTNL | 12132 NL80211_FLAG_CLEAR_SKB, 12133 }, 12134 { 12135 .cmd = NL80211_CMD_DEL_KEY, 12136 .doit = nl80211_del_key, 12137 .policy = nl80211_policy, 12138 .flags = GENL_UNS_ADMIN_PERM, 12139 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12140 NL80211_FLAG_NEED_RTNL, 12141 }, 12142 { 12143 .cmd = NL80211_CMD_SET_BEACON, 12144 .policy = nl80211_policy, 12145 .flags = GENL_UNS_ADMIN_PERM, 12146 .doit = nl80211_set_beacon, 12147 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12148 NL80211_FLAG_NEED_RTNL, 12149 }, 12150 { 12151 .cmd = NL80211_CMD_START_AP, 12152 .policy = nl80211_policy, 12153 .flags = GENL_UNS_ADMIN_PERM, 12154 .doit = nl80211_start_ap, 12155 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12156 NL80211_FLAG_NEED_RTNL, 12157 }, 12158 { 12159 .cmd = NL80211_CMD_STOP_AP, 12160 .policy = nl80211_policy, 12161 .flags = GENL_UNS_ADMIN_PERM, 12162 .doit = nl80211_stop_ap, 12163 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12164 NL80211_FLAG_NEED_RTNL, 12165 }, 12166 { 12167 .cmd = NL80211_CMD_GET_STATION, 12168 .doit = nl80211_get_station, 12169 .dumpit = nl80211_dump_station, 12170 .policy = nl80211_policy, 12171 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12172 NL80211_FLAG_NEED_RTNL, 12173 }, 12174 { 12175 .cmd = NL80211_CMD_SET_STATION, 12176 .doit = nl80211_set_station, 12177 .policy = nl80211_policy, 12178 .flags = GENL_UNS_ADMIN_PERM, 12179 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12180 NL80211_FLAG_NEED_RTNL, 12181 }, 12182 { 12183 .cmd = NL80211_CMD_NEW_STATION, 12184 .doit = nl80211_new_station, 12185 .policy = nl80211_policy, 12186 .flags = GENL_UNS_ADMIN_PERM, 12187 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12188 NL80211_FLAG_NEED_RTNL, 12189 }, 12190 { 12191 .cmd = NL80211_CMD_DEL_STATION, 12192 .doit = nl80211_del_station, 12193 .policy = nl80211_policy, 12194 .flags = GENL_UNS_ADMIN_PERM, 12195 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12196 NL80211_FLAG_NEED_RTNL, 12197 }, 12198 { 12199 .cmd = NL80211_CMD_GET_MPATH, 12200 .doit = nl80211_get_mpath, 12201 .dumpit = nl80211_dump_mpath, 12202 .policy = nl80211_policy, 12203 .flags = GENL_UNS_ADMIN_PERM, 12204 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12205 NL80211_FLAG_NEED_RTNL, 12206 }, 12207 { 12208 .cmd = NL80211_CMD_GET_MPP, 12209 .doit = nl80211_get_mpp, 12210 .dumpit = nl80211_dump_mpp, 12211 .policy = nl80211_policy, 12212 .flags = GENL_UNS_ADMIN_PERM, 12213 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12214 NL80211_FLAG_NEED_RTNL, 12215 }, 12216 { 12217 .cmd = NL80211_CMD_SET_MPATH, 12218 .doit = nl80211_set_mpath, 12219 .policy = nl80211_policy, 12220 .flags = GENL_UNS_ADMIN_PERM, 12221 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12222 NL80211_FLAG_NEED_RTNL, 12223 }, 12224 { 12225 .cmd = NL80211_CMD_NEW_MPATH, 12226 .doit = nl80211_new_mpath, 12227 .policy = nl80211_policy, 12228 .flags = GENL_UNS_ADMIN_PERM, 12229 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12230 NL80211_FLAG_NEED_RTNL, 12231 }, 12232 { 12233 .cmd = NL80211_CMD_DEL_MPATH, 12234 .doit = nl80211_del_mpath, 12235 .policy = nl80211_policy, 12236 .flags = GENL_UNS_ADMIN_PERM, 12237 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12238 NL80211_FLAG_NEED_RTNL, 12239 }, 12240 { 12241 .cmd = NL80211_CMD_SET_BSS, 12242 .doit = nl80211_set_bss, 12243 .policy = nl80211_policy, 12244 .flags = GENL_UNS_ADMIN_PERM, 12245 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12246 NL80211_FLAG_NEED_RTNL, 12247 }, 12248 { 12249 .cmd = NL80211_CMD_GET_REG, 12250 .doit = nl80211_get_reg_do, 12251 .dumpit = nl80211_get_reg_dump, 12252 .policy = nl80211_policy, 12253 .internal_flags = NL80211_FLAG_NEED_RTNL, 12254 /* can be retrieved by unprivileged users */ 12255 }, 12256 #ifdef CONFIG_CFG80211_CRDA_SUPPORT 12257 { 12258 .cmd = NL80211_CMD_SET_REG, 12259 .doit = nl80211_set_reg, 12260 .policy = nl80211_policy, 12261 .flags = GENL_ADMIN_PERM, 12262 .internal_flags = NL80211_FLAG_NEED_RTNL, 12263 }, 12264 #endif 12265 { 12266 .cmd = NL80211_CMD_REQ_SET_REG, 12267 .doit = nl80211_req_set_reg, 12268 .policy = nl80211_policy, 12269 .flags = GENL_ADMIN_PERM, 12270 }, 12271 { 12272 .cmd = NL80211_CMD_GET_MESH_CONFIG, 12273 .doit = nl80211_get_mesh_config, 12274 .policy = nl80211_policy, 12275 /* can be retrieved by unprivileged users */ 12276 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12277 NL80211_FLAG_NEED_RTNL, 12278 }, 12279 { 12280 .cmd = NL80211_CMD_SET_MESH_CONFIG, 12281 .doit = nl80211_update_mesh_config, 12282 .policy = nl80211_policy, 12283 .flags = GENL_UNS_ADMIN_PERM, 12284 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12285 NL80211_FLAG_NEED_RTNL, 12286 }, 12287 { 12288 .cmd = NL80211_CMD_TRIGGER_SCAN, 12289 .doit = nl80211_trigger_scan, 12290 .policy = nl80211_policy, 12291 .flags = GENL_UNS_ADMIN_PERM, 12292 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12293 NL80211_FLAG_NEED_RTNL, 12294 }, 12295 { 12296 .cmd = NL80211_CMD_ABORT_SCAN, 12297 .doit = nl80211_abort_scan, 12298 .policy = nl80211_policy, 12299 .flags = GENL_UNS_ADMIN_PERM, 12300 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12301 NL80211_FLAG_NEED_RTNL, 12302 }, 12303 { 12304 .cmd = NL80211_CMD_GET_SCAN, 12305 .policy = nl80211_policy, 12306 .dumpit = nl80211_dump_scan, 12307 }, 12308 { 12309 .cmd = NL80211_CMD_START_SCHED_SCAN, 12310 .doit = nl80211_start_sched_scan, 12311 .policy = nl80211_policy, 12312 .flags = GENL_UNS_ADMIN_PERM, 12313 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12314 NL80211_FLAG_NEED_RTNL, 12315 }, 12316 { 12317 .cmd = NL80211_CMD_STOP_SCHED_SCAN, 12318 .doit = nl80211_stop_sched_scan, 12319 .policy = nl80211_policy, 12320 .flags = GENL_UNS_ADMIN_PERM, 12321 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12322 NL80211_FLAG_NEED_RTNL, 12323 }, 12324 { 12325 .cmd = NL80211_CMD_AUTHENTICATE, 12326 .doit = nl80211_authenticate, 12327 .policy = nl80211_policy, 12328 .flags = GENL_UNS_ADMIN_PERM, 12329 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12330 NL80211_FLAG_NEED_RTNL | 12331 NL80211_FLAG_CLEAR_SKB, 12332 }, 12333 { 12334 .cmd = NL80211_CMD_ASSOCIATE, 12335 .doit = nl80211_associate, 12336 .policy = nl80211_policy, 12337 .flags = GENL_UNS_ADMIN_PERM, 12338 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12339 NL80211_FLAG_NEED_RTNL, 12340 }, 12341 { 12342 .cmd = NL80211_CMD_DEAUTHENTICATE, 12343 .doit = nl80211_deauthenticate, 12344 .policy = nl80211_policy, 12345 .flags = GENL_UNS_ADMIN_PERM, 12346 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12347 NL80211_FLAG_NEED_RTNL, 12348 }, 12349 { 12350 .cmd = NL80211_CMD_DISASSOCIATE, 12351 .doit = nl80211_disassociate, 12352 .policy = nl80211_policy, 12353 .flags = GENL_UNS_ADMIN_PERM, 12354 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12355 NL80211_FLAG_NEED_RTNL, 12356 }, 12357 { 12358 .cmd = NL80211_CMD_JOIN_IBSS, 12359 .doit = nl80211_join_ibss, 12360 .policy = nl80211_policy, 12361 .flags = GENL_UNS_ADMIN_PERM, 12362 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12363 NL80211_FLAG_NEED_RTNL, 12364 }, 12365 { 12366 .cmd = NL80211_CMD_LEAVE_IBSS, 12367 .doit = nl80211_leave_ibss, 12368 .policy = nl80211_policy, 12369 .flags = GENL_UNS_ADMIN_PERM, 12370 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12371 NL80211_FLAG_NEED_RTNL, 12372 }, 12373 #ifdef CONFIG_NL80211_TESTMODE 12374 { 12375 .cmd = NL80211_CMD_TESTMODE, 12376 .doit = nl80211_testmode_do, 12377 .dumpit = nl80211_testmode_dump, 12378 .policy = nl80211_policy, 12379 .flags = GENL_UNS_ADMIN_PERM, 12380 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12381 NL80211_FLAG_NEED_RTNL, 12382 }, 12383 #endif 12384 { 12385 .cmd = NL80211_CMD_CONNECT, 12386 .doit = nl80211_connect, 12387 .policy = nl80211_policy, 12388 .flags = GENL_UNS_ADMIN_PERM, 12389 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12390 NL80211_FLAG_NEED_RTNL, 12391 }, 12392 { 12393 .cmd = NL80211_CMD_UPDATE_CONNECT_PARAMS, 12394 .doit = nl80211_update_connect_params, 12395 .policy = nl80211_policy, 12396 .flags = GENL_ADMIN_PERM, 12397 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12398 NL80211_FLAG_NEED_RTNL, 12399 }, 12400 { 12401 .cmd = NL80211_CMD_DISCONNECT, 12402 .doit = nl80211_disconnect, 12403 .policy = nl80211_policy, 12404 .flags = GENL_UNS_ADMIN_PERM, 12405 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12406 NL80211_FLAG_NEED_RTNL, 12407 }, 12408 { 12409 .cmd = NL80211_CMD_SET_WIPHY_NETNS, 12410 .doit = nl80211_wiphy_netns, 12411 .policy = nl80211_policy, 12412 .flags = GENL_UNS_ADMIN_PERM, 12413 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12414 NL80211_FLAG_NEED_RTNL, 12415 }, 12416 { 12417 .cmd = NL80211_CMD_GET_SURVEY, 12418 .policy = nl80211_policy, 12419 .dumpit = nl80211_dump_survey, 12420 }, 12421 { 12422 .cmd = NL80211_CMD_SET_PMKSA, 12423 .doit = nl80211_setdel_pmksa, 12424 .policy = nl80211_policy, 12425 .flags = GENL_UNS_ADMIN_PERM, 12426 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12427 NL80211_FLAG_NEED_RTNL, 12428 }, 12429 { 12430 .cmd = NL80211_CMD_DEL_PMKSA, 12431 .doit = nl80211_setdel_pmksa, 12432 .policy = nl80211_policy, 12433 .flags = GENL_UNS_ADMIN_PERM, 12434 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12435 NL80211_FLAG_NEED_RTNL, 12436 }, 12437 { 12438 .cmd = NL80211_CMD_FLUSH_PMKSA, 12439 .doit = nl80211_flush_pmksa, 12440 .policy = nl80211_policy, 12441 .flags = GENL_UNS_ADMIN_PERM, 12442 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12443 NL80211_FLAG_NEED_RTNL, 12444 }, 12445 { 12446 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL, 12447 .doit = nl80211_remain_on_channel, 12448 .policy = nl80211_policy, 12449 .flags = GENL_UNS_ADMIN_PERM, 12450 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12451 NL80211_FLAG_NEED_RTNL, 12452 }, 12453 { 12454 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL, 12455 .doit = nl80211_cancel_remain_on_channel, 12456 .policy = nl80211_policy, 12457 .flags = GENL_UNS_ADMIN_PERM, 12458 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12459 NL80211_FLAG_NEED_RTNL, 12460 }, 12461 { 12462 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK, 12463 .doit = nl80211_set_tx_bitrate_mask, 12464 .policy = nl80211_policy, 12465 .flags = GENL_UNS_ADMIN_PERM, 12466 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12467 NL80211_FLAG_NEED_RTNL, 12468 }, 12469 { 12470 .cmd = NL80211_CMD_REGISTER_FRAME, 12471 .doit = nl80211_register_mgmt, 12472 .policy = nl80211_policy, 12473 .flags = GENL_UNS_ADMIN_PERM, 12474 .internal_flags = NL80211_FLAG_NEED_WDEV | 12475 NL80211_FLAG_NEED_RTNL, 12476 }, 12477 { 12478 .cmd = NL80211_CMD_FRAME, 12479 .doit = nl80211_tx_mgmt, 12480 .policy = nl80211_policy, 12481 .flags = GENL_UNS_ADMIN_PERM, 12482 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12483 NL80211_FLAG_NEED_RTNL, 12484 }, 12485 { 12486 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL, 12487 .doit = nl80211_tx_mgmt_cancel_wait, 12488 .policy = nl80211_policy, 12489 .flags = GENL_UNS_ADMIN_PERM, 12490 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12491 NL80211_FLAG_NEED_RTNL, 12492 }, 12493 { 12494 .cmd = NL80211_CMD_SET_POWER_SAVE, 12495 .doit = nl80211_set_power_save, 12496 .policy = nl80211_policy, 12497 .flags = GENL_UNS_ADMIN_PERM, 12498 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12499 NL80211_FLAG_NEED_RTNL, 12500 }, 12501 { 12502 .cmd = NL80211_CMD_GET_POWER_SAVE, 12503 .doit = nl80211_get_power_save, 12504 .policy = nl80211_policy, 12505 /* can be retrieved by unprivileged users */ 12506 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12507 NL80211_FLAG_NEED_RTNL, 12508 }, 12509 { 12510 .cmd = NL80211_CMD_SET_CQM, 12511 .doit = nl80211_set_cqm, 12512 .policy = nl80211_policy, 12513 .flags = GENL_UNS_ADMIN_PERM, 12514 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12515 NL80211_FLAG_NEED_RTNL, 12516 }, 12517 { 12518 .cmd = NL80211_CMD_SET_CHANNEL, 12519 .doit = nl80211_set_channel, 12520 .policy = nl80211_policy, 12521 .flags = GENL_UNS_ADMIN_PERM, 12522 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12523 NL80211_FLAG_NEED_RTNL, 12524 }, 12525 { 12526 .cmd = NL80211_CMD_SET_WDS_PEER, 12527 .doit = nl80211_set_wds_peer, 12528 .policy = nl80211_policy, 12529 .flags = GENL_UNS_ADMIN_PERM, 12530 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12531 NL80211_FLAG_NEED_RTNL, 12532 }, 12533 { 12534 .cmd = NL80211_CMD_JOIN_MESH, 12535 .doit = nl80211_join_mesh, 12536 .policy = nl80211_policy, 12537 .flags = GENL_UNS_ADMIN_PERM, 12538 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12539 NL80211_FLAG_NEED_RTNL, 12540 }, 12541 { 12542 .cmd = NL80211_CMD_LEAVE_MESH, 12543 .doit = nl80211_leave_mesh, 12544 .policy = nl80211_policy, 12545 .flags = GENL_UNS_ADMIN_PERM, 12546 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12547 NL80211_FLAG_NEED_RTNL, 12548 }, 12549 { 12550 .cmd = NL80211_CMD_JOIN_OCB, 12551 .doit = nl80211_join_ocb, 12552 .policy = nl80211_policy, 12553 .flags = GENL_UNS_ADMIN_PERM, 12554 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12555 NL80211_FLAG_NEED_RTNL, 12556 }, 12557 { 12558 .cmd = NL80211_CMD_LEAVE_OCB, 12559 .doit = nl80211_leave_ocb, 12560 .policy = nl80211_policy, 12561 .flags = GENL_UNS_ADMIN_PERM, 12562 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12563 NL80211_FLAG_NEED_RTNL, 12564 }, 12565 #ifdef CONFIG_PM 12566 { 12567 .cmd = NL80211_CMD_GET_WOWLAN, 12568 .doit = nl80211_get_wowlan, 12569 .policy = nl80211_policy, 12570 /* can be retrieved by unprivileged users */ 12571 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12572 NL80211_FLAG_NEED_RTNL, 12573 }, 12574 { 12575 .cmd = NL80211_CMD_SET_WOWLAN, 12576 .doit = nl80211_set_wowlan, 12577 .policy = nl80211_policy, 12578 .flags = GENL_UNS_ADMIN_PERM, 12579 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12580 NL80211_FLAG_NEED_RTNL, 12581 }, 12582 #endif 12583 { 12584 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD, 12585 .doit = nl80211_set_rekey_data, 12586 .policy = nl80211_policy, 12587 .flags = GENL_UNS_ADMIN_PERM, 12588 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12589 NL80211_FLAG_NEED_RTNL | 12590 NL80211_FLAG_CLEAR_SKB, 12591 }, 12592 { 12593 .cmd = NL80211_CMD_TDLS_MGMT, 12594 .doit = nl80211_tdls_mgmt, 12595 .policy = nl80211_policy, 12596 .flags = GENL_UNS_ADMIN_PERM, 12597 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12598 NL80211_FLAG_NEED_RTNL, 12599 }, 12600 { 12601 .cmd = NL80211_CMD_TDLS_OPER, 12602 .doit = nl80211_tdls_oper, 12603 .policy = nl80211_policy, 12604 .flags = GENL_UNS_ADMIN_PERM, 12605 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12606 NL80211_FLAG_NEED_RTNL, 12607 }, 12608 { 12609 .cmd = NL80211_CMD_UNEXPECTED_FRAME, 12610 .doit = nl80211_register_unexpected_frame, 12611 .policy = nl80211_policy, 12612 .flags = GENL_UNS_ADMIN_PERM, 12613 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12614 NL80211_FLAG_NEED_RTNL, 12615 }, 12616 { 12617 .cmd = NL80211_CMD_PROBE_CLIENT, 12618 .doit = nl80211_probe_client, 12619 .policy = nl80211_policy, 12620 .flags = GENL_UNS_ADMIN_PERM, 12621 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12622 NL80211_FLAG_NEED_RTNL, 12623 }, 12624 { 12625 .cmd = NL80211_CMD_REGISTER_BEACONS, 12626 .doit = nl80211_register_beacons, 12627 .policy = nl80211_policy, 12628 .flags = GENL_UNS_ADMIN_PERM, 12629 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12630 NL80211_FLAG_NEED_RTNL, 12631 }, 12632 { 12633 .cmd = NL80211_CMD_SET_NOACK_MAP, 12634 .doit = nl80211_set_noack_map, 12635 .policy = nl80211_policy, 12636 .flags = GENL_UNS_ADMIN_PERM, 12637 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12638 NL80211_FLAG_NEED_RTNL, 12639 }, 12640 { 12641 .cmd = NL80211_CMD_START_P2P_DEVICE, 12642 .doit = nl80211_start_p2p_device, 12643 .policy = nl80211_policy, 12644 .flags = GENL_UNS_ADMIN_PERM, 12645 .internal_flags = NL80211_FLAG_NEED_WDEV | 12646 NL80211_FLAG_NEED_RTNL, 12647 }, 12648 { 12649 .cmd = NL80211_CMD_STOP_P2P_DEVICE, 12650 .doit = nl80211_stop_p2p_device, 12651 .policy = nl80211_policy, 12652 .flags = GENL_UNS_ADMIN_PERM, 12653 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12654 NL80211_FLAG_NEED_RTNL, 12655 }, 12656 { 12657 .cmd = NL80211_CMD_START_NAN, 12658 .doit = nl80211_start_nan, 12659 .policy = nl80211_policy, 12660 .flags = GENL_ADMIN_PERM, 12661 .internal_flags = NL80211_FLAG_NEED_WDEV | 12662 NL80211_FLAG_NEED_RTNL, 12663 }, 12664 { 12665 .cmd = NL80211_CMD_STOP_NAN, 12666 .doit = nl80211_stop_nan, 12667 .policy = nl80211_policy, 12668 .flags = GENL_ADMIN_PERM, 12669 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12670 NL80211_FLAG_NEED_RTNL, 12671 }, 12672 { 12673 .cmd = NL80211_CMD_ADD_NAN_FUNCTION, 12674 .doit = nl80211_nan_add_func, 12675 .policy = nl80211_policy, 12676 .flags = GENL_ADMIN_PERM, 12677 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12678 NL80211_FLAG_NEED_RTNL, 12679 }, 12680 { 12681 .cmd = NL80211_CMD_DEL_NAN_FUNCTION, 12682 .doit = nl80211_nan_del_func, 12683 .policy = nl80211_policy, 12684 .flags = GENL_ADMIN_PERM, 12685 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12686 NL80211_FLAG_NEED_RTNL, 12687 }, 12688 { 12689 .cmd = NL80211_CMD_CHANGE_NAN_CONFIG, 12690 .doit = nl80211_nan_change_config, 12691 .policy = nl80211_policy, 12692 .flags = GENL_ADMIN_PERM, 12693 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12694 NL80211_FLAG_NEED_RTNL, 12695 }, 12696 { 12697 .cmd = NL80211_CMD_SET_MCAST_RATE, 12698 .doit = nl80211_set_mcast_rate, 12699 .policy = nl80211_policy, 12700 .flags = GENL_UNS_ADMIN_PERM, 12701 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12702 NL80211_FLAG_NEED_RTNL, 12703 }, 12704 { 12705 .cmd = NL80211_CMD_SET_MAC_ACL, 12706 .doit = nl80211_set_mac_acl, 12707 .policy = nl80211_policy, 12708 .flags = GENL_UNS_ADMIN_PERM, 12709 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12710 NL80211_FLAG_NEED_RTNL, 12711 }, 12712 { 12713 .cmd = NL80211_CMD_RADAR_DETECT, 12714 .doit = nl80211_start_radar_detection, 12715 .policy = nl80211_policy, 12716 .flags = GENL_UNS_ADMIN_PERM, 12717 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12718 NL80211_FLAG_NEED_RTNL, 12719 }, 12720 { 12721 .cmd = NL80211_CMD_GET_PROTOCOL_FEATURES, 12722 .doit = nl80211_get_protocol_features, 12723 .policy = nl80211_policy, 12724 }, 12725 { 12726 .cmd = NL80211_CMD_UPDATE_FT_IES, 12727 .doit = nl80211_update_ft_ies, 12728 .policy = nl80211_policy, 12729 .flags = GENL_UNS_ADMIN_PERM, 12730 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12731 NL80211_FLAG_NEED_RTNL, 12732 }, 12733 { 12734 .cmd = NL80211_CMD_CRIT_PROTOCOL_START, 12735 .doit = nl80211_crit_protocol_start, 12736 .policy = nl80211_policy, 12737 .flags = GENL_UNS_ADMIN_PERM, 12738 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12739 NL80211_FLAG_NEED_RTNL, 12740 }, 12741 { 12742 .cmd = NL80211_CMD_CRIT_PROTOCOL_STOP, 12743 .doit = nl80211_crit_protocol_stop, 12744 .policy = nl80211_policy, 12745 .flags = GENL_UNS_ADMIN_PERM, 12746 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12747 NL80211_FLAG_NEED_RTNL, 12748 }, 12749 { 12750 .cmd = NL80211_CMD_GET_COALESCE, 12751 .doit = nl80211_get_coalesce, 12752 .policy = nl80211_policy, 12753 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12754 NL80211_FLAG_NEED_RTNL, 12755 }, 12756 { 12757 .cmd = NL80211_CMD_SET_COALESCE, 12758 .doit = nl80211_set_coalesce, 12759 .policy = nl80211_policy, 12760 .flags = GENL_UNS_ADMIN_PERM, 12761 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12762 NL80211_FLAG_NEED_RTNL, 12763 }, 12764 { 12765 .cmd = NL80211_CMD_CHANNEL_SWITCH, 12766 .doit = nl80211_channel_switch, 12767 .policy = nl80211_policy, 12768 .flags = GENL_UNS_ADMIN_PERM, 12769 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12770 NL80211_FLAG_NEED_RTNL, 12771 }, 12772 { 12773 .cmd = NL80211_CMD_VENDOR, 12774 .doit = nl80211_vendor_cmd, 12775 .dumpit = nl80211_vendor_cmd_dump, 12776 .policy = nl80211_policy, 12777 .flags = GENL_UNS_ADMIN_PERM, 12778 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12779 NL80211_FLAG_NEED_RTNL, 12780 }, 12781 { 12782 .cmd = NL80211_CMD_SET_QOS_MAP, 12783 .doit = nl80211_set_qos_map, 12784 .policy = nl80211_policy, 12785 .flags = GENL_UNS_ADMIN_PERM, 12786 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12787 NL80211_FLAG_NEED_RTNL, 12788 }, 12789 { 12790 .cmd = NL80211_CMD_ADD_TX_TS, 12791 .doit = nl80211_add_tx_ts, 12792 .policy = nl80211_policy, 12793 .flags = GENL_UNS_ADMIN_PERM, 12794 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12795 NL80211_FLAG_NEED_RTNL, 12796 }, 12797 { 12798 .cmd = NL80211_CMD_DEL_TX_TS, 12799 .doit = nl80211_del_tx_ts, 12800 .policy = nl80211_policy, 12801 .flags = GENL_UNS_ADMIN_PERM, 12802 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12803 NL80211_FLAG_NEED_RTNL, 12804 }, 12805 { 12806 .cmd = NL80211_CMD_TDLS_CHANNEL_SWITCH, 12807 .doit = nl80211_tdls_channel_switch, 12808 .policy = nl80211_policy, 12809 .flags = GENL_UNS_ADMIN_PERM, 12810 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12811 NL80211_FLAG_NEED_RTNL, 12812 }, 12813 { 12814 .cmd = NL80211_CMD_TDLS_CANCEL_CHANNEL_SWITCH, 12815 .doit = nl80211_tdls_cancel_channel_switch, 12816 .policy = nl80211_policy, 12817 .flags = GENL_UNS_ADMIN_PERM, 12818 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12819 NL80211_FLAG_NEED_RTNL, 12820 }, 12821 { 12822 .cmd = NL80211_CMD_SET_MULTICAST_TO_UNICAST, 12823 .doit = nl80211_set_multicast_to_unicast, 12824 .policy = nl80211_policy, 12825 .flags = GENL_UNS_ADMIN_PERM, 12826 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12827 NL80211_FLAG_NEED_RTNL, 12828 }, 12829 }; 12830 12831 static struct genl_family nl80211_fam __ro_after_init = { 12832 .name = NL80211_GENL_NAME, /* have users key off the name instead */ 12833 .hdrsize = 0, /* no private header */ 12834 .version = 1, /* no particular meaning now */ 12835 .maxattr = NL80211_ATTR_MAX, 12836 .netnsok = true, 12837 .pre_doit = nl80211_pre_doit, 12838 .post_doit = nl80211_post_doit, 12839 .module = THIS_MODULE, 12840 .ops = nl80211_ops, 12841 .n_ops = ARRAY_SIZE(nl80211_ops), 12842 .mcgrps = nl80211_mcgrps, 12843 .n_mcgrps = ARRAY_SIZE(nl80211_mcgrps), 12844 }; 12845 12846 /* notification functions */ 12847 12848 void nl80211_notify_wiphy(struct cfg80211_registered_device *rdev, 12849 enum nl80211_commands cmd) 12850 { 12851 struct sk_buff *msg; 12852 struct nl80211_dump_wiphy_state state = {}; 12853 12854 WARN_ON(cmd != NL80211_CMD_NEW_WIPHY && 12855 cmd != NL80211_CMD_DEL_WIPHY); 12856 12857 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12858 if (!msg) 12859 return; 12860 12861 if (nl80211_send_wiphy(rdev, cmd, msg, 0, 0, 0, &state) < 0) { 12862 nlmsg_free(msg); 12863 return; 12864 } 12865 12866 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12867 NL80211_MCGRP_CONFIG, GFP_KERNEL); 12868 } 12869 12870 void nl80211_notify_iface(struct cfg80211_registered_device *rdev, 12871 struct wireless_dev *wdev, 12872 enum nl80211_commands cmd) 12873 { 12874 struct sk_buff *msg; 12875 12876 WARN_ON(cmd != NL80211_CMD_NEW_INTERFACE && 12877 cmd != NL80211_CMD_DEL_INTERFACE); 12878 12879 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12880 if (!msg) 12881 return; 12882 12883 if (nl80211_send_iface(msg, 0, 0, 0, rdev, wdev, 12884 cmd == NL80211_CMD_DEL_INTERFACE) < 0) { 12885 nlmsg_free(msg); 12886 return; 12887 } 12888 12889 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12890 NL80211_MCGRP_CONFIG, GFP_KERNEL); 12891 } 12892 12893 static int nl80211_add_scan_req(struct sk_buff *msg, 12894 struct cfg80211_registered_device *rdev) 12895 { 12896 struct cfg80211_scan_request *req = rdev->scan_req; 12897 struct nlattr *nest; 12898 int i; 12899 12900 if (WARN_ON(!req)) 12901 return 0; 12902 12903 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS); 12904 if (!nest) 12905 goto nla_put_failure; 12906 for (i = 0; i < req->n_ssids; i++) { 12907 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid)) 12908 goto nla_put_failure; 12909 } 12910 nla_nest_end(msg, nest); 12911 12912 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES); 12913 if (!nest) 12914 goto nla_put_failure; 12915 for (i = 0; i < req->n_channels; i++) { 12916 if (nla_put_u32(msg, i, req->channels[i]->center_freq)) 12917 goto nla_put_failure; 12918 } 12919 nla_nest_end(msg, nest); 12920 12921 if (req->ie && 12922 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie)) 12923 goto nla_put_failure; 12924 12925 if (req->flags && 12926 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags)) 12927 goto nla_put_failure; 12928 12929 if (req->info.scan_start_tsf && 12930 (nla_put_u64_64bit(msg, NL80211_ATTR_SCAN_START_TIME_TSF, 12931 req->info.scan_start_tsf, NL80211_BSS_PAD) || 12932 nla_put(msg, NL80211_ATTR_SCAN_START_TIME_TSF_BSSID, ETH_ALEN, 12933 req->info.tsf_bssid))) 12934 goto nla_put_failure; 12935 12936 return 0; 12937 nla_put_failure: 12938 return -ENOBUFS; 12939 } 12940 12941 static int nl80211_prep_scan_msg(struct sk_buff *msg, 12942 struct cfg80211_registered_device *rdev, 12943 struct wireless_dev *wdev, 12944 u32 portid, u32 seq, int flags, 12945 u32 cmd) 12946 { 12947 void *hdr; 12948 12949 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 12950 if (!hdr) 12951 return -1; 12952 12953 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 12954 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 12955 wdev->netdev->ifindex)) || 12956 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 12957 NL80211_ATTR_PAD)) 12958 goto nla_put_failure; 12959 12960 /* ignore errors and send incomplete event anyway */ 12961 nl80211_add_scan_req(msg, rdev); 12962 12963 genlmsg_end(msg, hdr); 12964 return 0; 12965 12966 nla_put_failure: 12967 genlmsg_cancel(msg, hdr); 12968 return -EMSGSIZE; 12969 } 12970 12971 static int 12972 nl80211_prep_sched_scan_msg(struct sk_buff *msg, 12973 struct cfg80211_registered_device *rdev, 12974 struct net_device *netdev, 12975 u32 portid, u32 seq, int flags, u32 cmd) 12976 { 12977 void *hdr; 12978 12979 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 12980 if (!hdr) 12981 return -1; 12982 12983 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 12984 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex)) 12985 goto nla_put_failure; 12986 12987 genlmsg_end(msg, hdr); 12988 return 0; 12989 12990 nla_put_failure: 12991 genlmsg_cancel(msg, hdr); 12992 return -EMSGSIZE; 12993 } 12994 12995 void nl80211_send_scan_start(struct cfg80211_registered_device *rdev, 12996 struct wireless_dev *wdev) 12997 { 12998 struct sk_buff *msg; 12999 13000 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 13001 if (!msg) 13002 return; 13003 13004 if (nl80211_prep_scan_msg(msg, rdev, wdev, 0, 0, 0, 13005 NL80211_CMD_TRIGGER_SCAN) < 0) { 13006 nlmsg_free(msg); 13007 return; 13008 } 13009 13010 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13011 NL80211_MCGRP_SCAN, GFP_KERNEL); 13012 } 13013 13014 struct sk_buff *nl80211_build_scan_msg(struct cfg80211_registered_device *rdev, 13015 struct wireless_dev *wdev, bool aborted) 13016 { 13017 struct sk_buff *msg; 13018 13019 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 13020 if (!msg) 13021 return NULL; 13022 13023 if (nl80211_prep_scan_msg(msg, rdev, wdev, 0, 0, 0, 13024 aborted ? NL80211_CMD_SCAN_ABORTED : 13025 NL80211_CMD_NEW_SCAN_RESULTS) < 0) { 13026 nlmsg_free(msg); 13027 return NULL; 13028 } 13029 13030 return msg; 13031 } 13032 13033 /* send message created by nl80211_build_scan_msg() */ 13034 void nl80211_send_scan_msg(struct cfg80211_registered_device *rdev, 13035 struct sk_buff *msg) 13036 { 13037 if (!msg) 13038 return; 13039 13040 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13041 NL80211_MCGRP_SCAN, GFP_KERNEL); 13042 } 13043 13044 void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev, 13045 struct net_device *netdev, u32 cmd) 13046 { 13047 struct sk_buff *msg; 13048 13049 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 13050 if (!msg) 13051 return; 13052 13053 if (nl80211_prep_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) { 13054 nlmsg_free(msg); 13055 return; 13056 } 13057 13058 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13059 NL80211_MCGRP_SCAN, GFP_KERNEL); 13060 } 13061 13062 static bool nl80211_reg_change_event_fill(struct sk_buff *msg, 13063 struct regulatory_request *request) 13064 { 13065 /* Userspace can always count this one always being set */ 13066 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator)) 13067 goto nla_put_failure; 13068 13069 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') { 13070 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE, 13071 NL80211_REGDOM_TYPE_WORLD)) 13072 goto nla_put_failure; 13073 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') { 13074 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE, 13075 NL80211_REGDOM_TYPE_CUSTOM_WORLD)) 13076 goto nla_put_failure; 13077 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') || 13078 request->intersect) { 13079 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE, 13080 NL80211_REGDOM_TYPE_INTERSECTION)) 13081 goto nla_put_failure; 13082 } else { 13083 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE, 13084 NL80211_REGDOM_TYPE_COUNTRY) || 13085 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, 13086 request->alpha2)) 13087 goto nla_put_failure; 13088 } 13089 13090 if (request->wiphy_idx != WIPHY_IDX_INVALID) { 13091 struct wiphy *wiphy = wiphy_idx_to_wiphy(request->wiphy_idx); 13092 13093 if (wiphy && 13094 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx)) 13095 goto nla_put_failure; 13096 13097 if (wiphy && 13098 wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED && 13099 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG)) 13100 goto nla_put_failure; 13101 } 13102 13103 return true; 13104 13105 nla_put_failure: 13106 return false; 13107 } 13108 13109 /* 13110 * This can happen on global regulatory changes or device specific settings 13111 * based on custom regulatory domains. 13112 */ 13113 void nl80211_common_reg_change_event(enum nl80211_commands cmd_id, 13114 struct regulatory_request *request) 13115 { 13116 struct sk_buff *msg; 13117 void *hdr; 13118 13119 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 13120 if (!msg) 13121 return; 13122 13123 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd_id); 13124 if (!hdr) { 13125 nlmsg_free(msg); 13126 return; 13127 } 13128 13129 if (nl80211_reg_change_event_fill(msg, request) == false) 13130 goto nla_put_failure; 13131 13132 genlmsg_end(msg, hdr); 13133 13134 rcu_read_lock(); 13135 genlmsg_multicast_allns(&nl80211_fam, msg, 0, 13136 NL80211_MCGRP_REGULATORY, GFP_ATOMIC); 13137 rcu_read_unlock(); 13138 13139 return; 13140 13141 nla_put_failure: 13142 genlmsg_cancel(msg, hdr); 13143 nlmsg_free(msg); 13144 } 13145 13146 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev, 13147 struct net_device *netdev, 13148 const u8 *buf, size_t len, 13149 enum nl80211_commands cmd, gfp_t gfp, 13150 int uapsd_queues) 13151 { 13152 struct sk_buff *msg; 13153 void *hdr; 13154 13155 msg = nlmsg_new(100 + len, gfp); 13156 if (!msg) 13157 return; 13158 13159 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd); 13160 if (!hdr) { 13161 nlmsg_free(msg); 13162 return; 13163 } 13164 13165 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13166 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13167 nla_put(msg, NL80211_ATTR_FRAME, len, buf)) 13168 goto nla_put_failure; 13169 13170 if (uapsd_queues >= 0) { 13171 struct nlattr *nla_wmm = 13172 nla_nest_start(msg, NL80211_ATTR_STA_WME); 13173 if (!nla_wmm) 13174 goto nla_put_failure; 13175 13176 if (nla_put_u8(msg, NL80211_STA_WME_UAPSD_QUEUES, 13177 uapsd_queues)) 13178 goto nla_put_failure; 13179 13180 nla_nest_end(msg, nla_wmm); 13181 } 13182 13183 genlmsg_end(msg, hdr); 13184 13185 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13186 NL80211_MCGRP_MLME, gfp); 13187 return; 13188 13189 nla_put_failure: 13190 genlmsg_cancel(msg, hdr); 13191 nlmsg_free(msg); 13192 } 13193 13194 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev, 13195 struct net_device *netdev, const u8 *buf, 13196 size_t len, gfp_t gfp) 13197 { 13198 nl80211_send_mlme_event(rdev, netdev, buf, len, 13199 NL80211_CMD_AUTHENTICATE, gfp, -1); 13200 } 13201 13202 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev, 13203 struct net_device *netdev, const u8 *buf, 13204 size_t len, gfp_t gfp, int uapsd_queues) 13205 { 13206 nl80211_send_mlme_event(rdev, netdev, buf, len, 13207 NL80211_CMD_ASSOCIATE, gfp, uapsd_queues); 13208 } 13209 13210 void nl80211_send_deauth(struct cfg80211_registered_device *rdev, 13211 struct net_device *netdev, const u8 *buf, 13212 size_t len, gfp_t gfp) 13213 { 13214 nl80211_send_mlme_event(rdev, netdev, buf, len, 13215 NL80211_CMD_DEAUTHENTICATE, gfp, -1); 13216 } 13217 13218 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev, 13219 struct net_device *netdev, const u8 *buf, 13220 size_t len, gfp_t gfp) 13221 { 13222 nl80211_send_mlme_event(rdev, netdev, buf, len, 13223 NL80211_CMD_DISASSOCIATE, gfp, -1); 13224 } 13225 13226 void cfg80211_rx_unprot_mlme_mgmt(struct net_device *dev, const u8 *buf, 13227 size_t len) 13228 { 13229 struct wireless_dev *wdev = dev->ieee80211_ptr; 13230 struct wiphy *wiphy = wdev->wiphy; 13231 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13232 const struct ieee80211_mgmt *mgmt = (void *)buf; 13233 u32 cmd; 13234 13235 if (WARN_ON(len < 2)) 13236 return; 13237 13238 if (ieee80211_is_deauth(mgmt->frame_control)) 13239 cmd = NL80211_CMD_UNPROT_DEAUTHENTICATE; 13240 else 13241 cmd = NL80211_CMD_UNPROT_DISASSOCIATE; 13242 13243 trace_cfg80211_rx_unprot_mlme_mgmt(dev, buf, len); 13244 nl80211_send_mlme_event(rdev, dev, buf, len, cmd, GFP_ATOMIC, -1); 13245 } 13246 EXPORT_SYMBOL(cfg80211_rx_unprot_mlme_mgmt); 13247 13248 static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev, 13249 struct net_device *netdev, int cmd, 13250 const u8 *addr, gfp_t gfp) 13251 { 13252 struct sk_buff *msg; 13253 void *hdr; 13254 13255 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13256 if (!msg) 13257 return; 13258 13259 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd); 13260 if (!hdr) { 13261 nlmsg_free(msg); 13262 return; 13263 } 13264 13265 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13266 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13267 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) || 13268 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) 13269 goto nla_put_failure; 13270 13271 genlmsg_end(msg, hdr); 13272 13273 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13274 NL80211_MCGRP_MLME, gfp); 13275 return; 13276 13277 nla_put_failure: 13278 genlmsg_cancel(msg, hdr); 13279 nlmsg_free(msg); 13280 } 13281 13282 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev, 13283 struct net_device *netdev, const u8 *addr, 13284 gfp_t gfp) 13285 { 13286 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE, 13287 addr, gfp); 13288 } 13289 13290 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev, 13291 struct net_device *netdev, const u8 *addr, 13292 gfp_t gfp) 13293 { 13294 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE, 13295 addr, gfp); 13296 } 13297 13298 void nl80211_send_connect_result(struct cfg80211_registered_device *rdev, 13299 struct net_device *netdev, const u8 *bssid, 13300 const u8 *req_ie, size_t req_ie_len, 13301 const u8 *resp_ie, size_t resp_ie_len, 13302 int status, 13303 enum nl80211_timeout_reason timeout_reason, 13304 gfp_t gfp) 13305 { 13306 struct sk_buff *msg; 13307 void *hdr; 13308 13309 msg = nlmsg_new(100 + req_ie_len + resp_ie_len, gfp); 13310 if (!msg) 13311 return; 13312 13313 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT); 13314 if (!hdr) { 13315 nlmsg_free(msg); 13316 return; 13317 } 13318 13319 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13320 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13321 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) || 13322 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, 13323 status < 0 ? WLAN_STATUS_UNSPECIFIED_FAILURE : 13324 status) || 13325 (status < 0 && 13326 (nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) || 13327 nla_put_u32(msg, NL80211_ATTR_TIMEOUT_REASON, timeout_reason))) || 13328 (req_ie && 13329 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) || 13330 (resp_ie && 13331 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie))) 13332 goto nla_put_failure; 13333 13334 genlmsg_end(msg, hdr); 13335 13336 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13337 NL80211_MCGRP_MLME, gfp); 13338 return; 13339 13340 nla_put_failure: 13341 genlmsg_cancel(msg, hdr); 13342 nlmsg_free(msg); 13343 } 13344 13345 void nl80211_send_roamed(struct cfg80211_registered_device *rdev, 13346 struct net_device *netdev, const u8 *bssid, 13347 const u8 *req_ie, size_t req_ie_len, 13348 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp) 13349 { 13350 struct sk_buff *msg; 13351 void *hdr; 13352 13353 msg = nlmsg_new(100 + req_ie_len + resp_ie_len, gfp); 13354 if (!msg) 13355 return; 13356 13357 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM); 13358 if (!hdr) { 13359 nlmsg_free(msg); 13360 return; 13361 } 13362 13363 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13364 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13365 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) || 13366 (req_ie && 13367 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) || 13368 (resp_ie && 13369 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie))) 13370 goto nla_put_failure; 13371 13372 genlmsg_end(msg, hdr); 13373 13374 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13375 NL80211_MCGRP_MLME, gfp); 13376 return; 13377 13378 nla_put_failure: 13379 genlmsg_cancel(msg, hdr); 13380 nlmsg_free(msg); 13381 } 13382 13383 void nl80211_send_disconnected(struct cfg80211_registered_device *rdev, 13384 struct net_device *netdev, u16 reason, 13385 const u8 *ie, size_t ie_len, bool from_ap) 13386 { 13387 struct sk_buff *msg; 13388 void *hdr; 13389 13390 msg = nlmsg_new(100 + ie_len, GFP_KERNEL); 13391 if (!msg) 13392 return; 13393 13394 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT); 13395 if (!hdr) { 13396 nlmsg_free(msg); 13397 return; 13398 } 13399 13400 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13401 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13402 (from_ap && reason && 13403 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) || 13404 (from_ap && 13405 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) || 13406 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie))) 13407 goto nla_put_failure; 13408 13409 genlmsg_end(msg, hdr); 13410 13411 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13412 NL80211_MCGRP_MLME, GFP_KERNEL); 13413 return; 13414 13415 nla_put_failure: 13416 genlmsg_cancel(msg, hdr); 13417 nlmsg_free(msg); 13418 } 13419 13420 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev, 13421 struct net_device *netdev, const u8 *bssid, 13422 gfp_t gfp) 13423 { 13424 struct sk_buff *msg; 13425 void *hdr; 13426 13427 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13428 if (!msg) 13429 return; 13430 13431 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS); 13432 if (!hdr) { 13433 nlmsg_free(msg); 13434 return; 13435 } 13436 13437 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13438 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13439 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) 13440 goto nla_put_failure; 13441 13442 genlmsg_end(msg, hdr); 13443 13444 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13445 NL80211_MCGRP_MLME, gfp); 13446 return; 13447 13448 nla_put_failure: 13449 genlmsg_cancel(msg, hdr); 13450 nlmsg_free(msg); 13451 } 13452 13453 void cfg80211_notify_new_peer_candidate(struct net_device *dev, const u8 *addr, 13454 const u8* ie, u8 ie_len, gfp_t gfp) 13455 { 13456 struct wireless_dev *wdev = dev->ieee80211_ptr; 13457 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 13458 struct sk_buff *msg; 13459 void *hdr; 13460 13461 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_MESH_POINT)) 13462 return; 13463 13464 trace_cfg80211_notify_new_peer_candidate(dev, addr); 13465 13466 msg = nlmsg_new(100 + ie_len, gfp); 13467 if (!msg) 13468 return; 13469 13470 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE); 13471 if (!hdr) { 13472 nlmsg_free(msg); 13473 return; 13474 } 13475 13476 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13477 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 13478 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) || 13479 (ie_len && ie && 13480 nla_put(msg, NL80211_ATTR_IE, ie_len , ie))) 13481 goto nla_put_failure; 13482 13483 genlmsg_end(msg, hdr); 13484 13485 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13486 NL80211_MCGRP_MLME, gfp); 13487 return; 13488 13489 nla_put_failure: 13490 genlmsg_cancel(msg, hdr); 13491 nlmsg_free(msg); 13492 } 13493 EXPORT_SYMBOL(cfg80211_notify_new_peer_candidate); 13494 13495 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev, 13496 struct net_device *netdev, const u8 *addr, 13497 enum nl80211_key_type key_type, int key_id, 13498 const u8 *tsc, gfp_t gfp) 13499 { 13500 struct sk_buff *msg; 13501 void *hdr; 13502 13503 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13504 if (!msg) 13505 return; 13506 13507 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE); 13508 if (!hdr) { 13509 nlmsg_free(msg); 13510 return; 13511 } 13512 13513 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13514 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13515 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) || 13516 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) || 13517 (key_id != -1 && 13518 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) || 13519 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc))) 13520 goto nla_put_failure; 13521 13522 genlmsg_end(msg, hdr); 13523 13524 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13525 NL80211_MCGRP_MLME, gfp); 13526 return; 13527 13528 nla_put_failure: 13529 genlmsg_cancel(msg, hdr); 13530 nlmsg_free(msg); 13531 } 13532 13533 void nl80211_send_beacon_hint_event(struct wiphy *wiphy, 13534 struct ieee80211_channel *channel_before, 13535 struct ieee80211_channel *channel_after) 13536 { 13537 struct sk_buff *msg; 13538 void *hdr; 13539 struct nlattr *nl_freq; 13540 13541 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC); 13542 if (!msg) 13543 return; 13544 13545 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT); 13546 if (!hdr) { 13547 nlmsg_free(msg); 13548 return; 13549 } 13550 13551 /* 13552 * Since we are applying the beacon hint to a wiphy we know its 13553 * wiphy_idx is valid 13554 */ 13555 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy))) 13556 goto nla_put_failure; 13557 13558 /* Before */ 13559 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE); 13560 if (!nl_freq) 13561 goto nla_put_failure; 13562 if (nl80211_msg_put_channel(msg, channel_before, false)) 13563 goto nla_put_failure; 13564 nla_nest_end(msg, nl_freq); 13565 13566 /* After */ 13567 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER); 13568 if (!nl_freq) 13569 goto nla_put_failure; 13570 if (nl80211_msg_put_channel(msg, channel_after, false)) 13571 goto nla_put_failure; 13572 nla_nest_end(msg, nl_freq); 13573 13574 genlmsg_end(msg, hdr); 13575 13576 rcu_read_lock(); 13577 genlmsg_multicast_allns(&nl80211_fam, msg, 0, 13578 NL80211_MCGRP_REGULATORY, GFP_ATOMIC); 13579 rcu_read_unlock(); 13580 13581 return; 13582 13583 nla_put_failure: 13584 genlmsg_cancel(msg, hdr); 13585 nlmsg_free(msg); 13586 } 13587 13588 static void nl80211_send_remain_on_chan_event( 13589 int cmd, struct cfg80211_registered_device *rdev, 13590 struct wireless_dev *wdev, u64 cookie, 13591 struct ieee80211_channel *chan, 13592 unsigned int duration, gfp_t gfp) 13593 { 13594 struct sk_buff *msg; 13595 void *hdr; 13596 13597 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13598 if (!msg) 13599 return; 13600 13601 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd); 13602 if (!hdr) { 13603 nlmsg_free(msg); 13604 return; 13605 } 13606 13607 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13608 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 13609 wdev->netdev->ifindex)) || 13610 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 13611 NL80211_ATTR_PAD) || 13612 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) || 13613 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, 13614 NL80211_CHAN_NO_HT) || 13615 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 13616 NL80211_ATTR_PAD)) 13617 goto nla_put_failure; 13618 13619 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL && 13620 nla_put_u32(msg, NL80211_ATTR_DURATION, duration)) 13621 goto nla_put_failure; 13622 13623 genlmsg_end(msg, hdr); 13624 13625 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13626 NL80211_MCGRP_MLME, gfp); 13627 return; 13628 13629 nla_put_failure: 13630 genlmsg_cancel(msg, hdr); 13631 nlmsg_free(msg); 13632 } 13633 13634 void cfg80211_ready_on_channel(struct wireless_dev *wdev, u64 cookie, 13635 struct ieee80211_channel *chan, 13636 unsigned int duration, gfp_t gfp) 13637 { 13638 struct wiphy *wiphy = wdev->wiphy; 13639 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13640 13641 trace_cfg80211_ready_on_channel(wdev, cookie, chan, duration); 13642 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL, 13643 rdev, wdev, cookie, chan, 13644 duration, gfp); 13645 } 13646 EXPORT_SYMBOL(cfg80211_ready_on_channel); 13647 13648 void cfg80211_remain_on_channel_expired(struct wireless_dev *wdev, u64 cookie, 13649 struct ieee80211_channel *chan, 13650 gfp_t gfp) 13651 { 13652 struct wiphy *wiphy = wdev->wiphy; 13653 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13654 13655 trace_cfg80211_ready_on_channel_expired(wdev, cookie, chan); 13656 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL, 13657 rdev, wdev, cookie, chan, 0, gfp); 13658 } 13659 EXPORT_SYMBOL(cfg80211_remain_on_channel_expired); 13660 13661 void cfg80211_new_sta(struct net_device *dev, const u8 *mac_addr, 13662 struct station_info *sinfo, gfp_t gfp) 13663 { 13664 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy; 13665 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13666 struct sk_buff *msg; 13667 13668 trace_cfg80211_new_sta(dev, mac_addr, sinfo); 13669 13670 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13671 if (!msg) 13672 return; 13673 13674 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION, 0, 0, 0, 13675 rdev, dev, mac_addr, sinfo) < 0) { 13676 nlmsg_free(msg); 13677 return; 13678 } 13679 13680 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13681 NL80211_MCGRP_MLME, gfp); 13682 } 13683 EXPORT_SYMBOL(cfg80211_new_sta); 13684 13685 void cfg80211_del_sta_sinfo(struct net_device *dev, const u8 *mac_addr, 13686 struct station_info *sinfo, gfp_t gfp) 13687 { 13688 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy; 13689 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13690 struct sk_buff *msg; 13691 struct station_info empty_sinfo = {}; 13692 13693 if (!sinfo) 13694 sinfo = &empty_sinfo; 13695 13696 trace_cfg80211_del_sta(dev, mac_addr); 13697 13698 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13699 if (!msg) 13700 return; 13701 13702 if (nl80211_send_station(msg, NL80211_CMD_DEL_STATION, 0, 0, 0, 13703 rdev, dev, mac_addr, sinfo) < 0) { 13704 nlmsg_free(msg); 13705 return; 13706 } 13707 13708 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13709 NL80211_MCGRP_MLME, gfp); 13710 } 13711 EXPORT_SYMBOL(cfg80211_del_sta_sinfo); 13712 13713 void cfg80211_conn_failed(struct net_device *dev, const u8 *mac_addr, 13714 enum nl80211_connect_failed_reason reason, 13715 gfp_t gfp) 13716 { 13717 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy; 13718 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13719 struct sk_buff *msg; 13720 void *hdr; 13721 13722 msg = nlmsg_new(NLMSG_GOODSIZE, gfp); 13723 if (!msg) 13724 return; 13725 13726 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED); 13727 if (!hdr) { 13728 nlmsg_free(msg); 13729 return; 13730 } 13731 13732 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 13733 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) || 13734 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason)) 13735 goto nla_put_failure; 13736 13737 genlmsg_end(msg, hdr); 13738 13739 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13740 NL80211_MCGRP_MLME, gfp); 13741 return; 13742 13743 nla_put_failure: 13744 genlmsg_cancel(msg, hdr); 13745 nlmsg_free(msg); 13746 } 13747 EXPORT_SYMBOL(cfg80211_conn_failed); 13748 13749 static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd, 13750 const u8 *addr, gfp_t gfp) 13751 { 13752 struct wireless_dev *wdev = dev->ieee80211_ptr; 13753 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 13754 struct sk_buff *msg; 13755 void *hdr; 13756 u32 nlportid = ACCESS_ONCE(wdev->ap_unexpected_nlportid); 13757 13758 if (!nlportid) 13759 return false; 13760 13761 msg = nlmsg_new(100, gfp); 13762 if (!msg) 13763 return true; 13764 13765 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd); 13766 if (!hdr) { 13767 nlmsg_free(msg); 13768 return true; 13769 } 13770 13771 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13772 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 13773 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) 13774 goto nla_put_failure; 13775 13776 genlmsg_end(msg, hdr); 13777 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid); 13778 return true; 13779 13780 nla_put_failure: 13781 genlmsg_cancel(msg, hdr); 13782 nlmsg_free(msg); 13783 return true; 13784 } 13785 13786 bool cfg80211_rx_spurious_frame(struct net_device *dev, 13787 const u8 *addr, gfp_t gfp) 13788 { 13789 struct wireless_dev *wdev = dev->ieee80211_ptr; 13790 bool ret; 13791 13792 trace_cfg80211_rx_spurious_frame(dev, addr); 13793 13794 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP && 13795 wdev->iftype != NL80211_IFTYPE_P2P_GO)) { 13796 trace_cfg80211_return_bool(false); 13797 return false; 13798 } 13799 ret = __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME, 13800 addr, gfp); 13801 trace_cfg80211_return_bool(ret); 13802 return ret; 13803 } 13804 EXPORT_SYMBOL(cfg80211_rx_spurious_frame); 13805 13806 bool cfg80211_rx_unexpected_4addr_frame(struct net_device *dev, 13807 const u8 *addr, gfp_t gfp) 13808 { 13809 struct wireless_dev *wdev = dev->ieee80211_ptr; 13810 bool ret; 13811 13812 trace_cfg80211_rx_unexpected_4addr_frame(dev, addr); 13813 13814 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP && 13815 wdev->iftype != NL80211_IFTYPE_P2P_GO && 13816 wdev->iftype != NL80211_IFTYPE_AP_VLAN)) { 13817 trace_cfg80211_return_bool(false); 13818 return false; 13819 } 13820 ret = __nl80211_unexpected_frame(dev, 13821 NL80211_CMD_UNEXPECTED_4ADDR_FRAME, 13822 addr, gfp); 13823 trace_cfg80211_return_bool(ret); 13824 return ret; 13825 } 13826 EXPORT_SYMBOL(cfg80211_rx_unexpected_4addr_frame); 13827 13828 int nl80211_send_mgmt(struct cfg80211_registered_device *rdev, 13829 struct wireless_dev *wdev, u32 nlportid, 13830 int freq, int sig_dbm, 13831 const u8 *buf, size_t len, u32 flags, gfp_t gfp) 13832 { 13833 struct net_device *netdev = wdev->netdev; 13834 struct sk_buff *msg; 13835 void *hdr; 13836 13837 msg = nlmsg_new(100 + len, gfp); 13838 if (!msg) 13839 return -ENOMEM; 13840 13841 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME); 13842 if (!hdr) { 13843 nlmsg_free(msg); 13844 return -ENOMEM; 13845 } 13846 13847 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13848 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 13849 netdev->ifindex)) || 13850 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 13851 NL80211_ATTR_PAD) || 13852 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) || 13853 (sig_dbm && 13854 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) || 13855 nla_put(msg, NL80211_ATTR_FRAME, len, buf) || 13856 (flags && 13857 nla_put_u32(msg, NL80211_ATTR_RXMGMT_FLAGS, flags))) 13858 goto nla_put_failure; 13859 13860 genlmsg_end(msg, hdr); 13861 13862 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid); 13863 13864 nla_put_failure: 13865 genlmsg_cancel(msg, hdr); 13866 nlmsg_free(msg); 13867 return -ENOBUFS; 13868 } 13869 13870 void cfg80211_mgmt_tx_status(struct wireless_dev *wdev, u64 cookie, 13871 const u8 *buf, size_t len, bool ack, gfp_t gfp) 13872 { 13873 struct wiphy *wiphy = wdev->wiphy; 13874 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13875 struct net_device *netdev = wdev->netdev; 13876 struct sk_buff *msg; 13877 void *hdr; 13878 13879 trace_cfg80211_mgmt_tx_status(wdev, cookie, ack); 13880 13881 msg = nlmsg_new(100 + len, gfp); 13882 if (!msg) 13883 return; 13884 13885 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS); 13886 if (!hdr) { 13887 nlmsg_free(msg); 13888 return; 13889 } 13890 13891 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13892 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 13893 netdev->ifindex)) || 13894 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 13895 NL80211_ATTR_PAD) || 13896 nla_put(msg, NL80211_ATTR_FRAME, len, buf) || 13897 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 13898 NL80211_ATTR_PAD) || 13899 (ack && nla_put_flag(msg, NL80211_ATTR_ACK))) 13900 goto nla_put_failure; 13901 13902 genlmsg_end(msg, hdr); 13903 13904 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13905 NL80211_MCGRP_MLME, gfp); 13906 return; 13907 13908 nla_put_failure: 13909 genlmsg_cancel(msg, hdr); 13910 nlmsg_free(msg); 13911 } 13912 EXPORT_SYMBOL(cfg80211_mgmt_tx_status); 13913 13914 static struct sk_buff *cfg80211_prepare_cqm(struct net_device *dev, 13915 const char *mac, gfp_t gfp) 13916 { 13917 struct wireless_dev *wdev = dev->ieee80211_ptr; 13918 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 13919 struct sk_buff *msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13920 void **cb; 13921 13922 if (!msg) 13923 return NULL; 13924 13925 cb = (void **)msg->cb; 13926 13927 cb[0] = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM); 13928 if (!cb[0]) { 13929 nlmsg_free(msg); 13930 return NULL; 13931 } 13932 13933 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13934 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex)) 13935 goto nla_put_failure; 13936 13937 if (mac && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac)) 13938 goto nla_put_failure; 13939 13940 cb[1] = nla_nest_start(msg, NL80211_ATTR_CQM); 13941 if (!cb[1]) 13942 goto nla_put_failure; 13943 13944 cb[2] = rdev; 13945 13946 return msg; 13947 nla_put_failure: 13948 nlmsg_free(msg); 13949 return NULL; 13950 } 13951 13952 static void cfg80211_send_cqm(struct sk_buff *msg, gfp_t gfp) 13953 { 13954 void **cb = (void **)msg->cb; 13955 struct cfg80211_registered_device *rdev = cb[2]; 13956 13957 nla_nest_end(msg, cb[1]); 13958 genlmsg_end(msg, cb[0]); 13959 13960 memset(msg->cb, 0, sizeof(msg->cb)); 13961 13962 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13963 NL80211_MCGRP_MLME, gfp); 13964 } 13965 13966 void cfg80211_cqm_rssi_notify(struct net_device *dev, 13967 enum nl80211_cqm_rssi_threshold_event rssi_event, 13968 s32 rssi_level, gfp_t gfp) 13969 { 13970 struct sk_buff *msg; 13971 13972 trace_cfg80211_cqm_rssi_notify(dev, rssi_event, rssi_level); 13973 13974 if (WARN_ON(rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW && 13975 rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH)) 13976 return; 13977 13978 msg = cfg80211_prepare_cqm(dev, NULL, gfp); 13979 if (!msg) 13980 return; 13981 13982 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT, 13983 rssi_event)) 13984 goto nla_put_failure; 13985 13986 if (rssi_level && nla_put_s32(msg, NL80211_ATTR_CQM_RSSI_LEVEL, 13987 rssi_level)) 13988 goto nla_put_failure; 13989 13990 cfg80211_send_cqm(msg, gfp); 13991 13992 return; 13993 13994 nla_put_failure: 13995 nlmsg_free(msg); 13996 } 13997 EXPORT_SYMBOL(cfg80211_cqm_rssi_notify); 13998 13999 void cfg80211_cqm_txe_notify(struct net_device *dev, 14000 const u8 *peer, u32 num_packets, 14001 u32 rate, u32 intvl, gfp_t gfp) 14002 { 14003 struct sk_buff *msg; 14004 14005 msg = cfg80211_prepare_cqm(dev, peer, gfp); 14006 if (!msg) 14007 return; 14008 14009 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets)) 14010 goto nla_put_failure; 14011 14012 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate)) 14013 goto nla_put_failure; 14014 14015 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl)) 14016 goto nla_put_failure; 14017 14018 cfg80211_send_cqm(msg, gfp); 14019 return; 14020 14021 nla_put_failure: 14022 nlmsg_free(msg); 14023 } 14024 EXPORT_SYMBOL(cfg80211_cqm_txe_notify); 14025 14026 void cfg80211_cqm_pktloss_notify(struct net_device *dev, 14027 const u8 *peer, u32 num_packets, gfp_t gfp) 14028 { 14029 struct sk_buff *msg; 14030 14031 trace_cfg80211_cqm_pktloss_notify(dev, peer, num_packets); 14032 14033 msg = cfg80211_prepare_cqm(dev, peer, gfp); 14034 if (!msg) 14035 return; 14036 14037 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets)) 14038 goto nla_put_failure; 14039 14040 cfg80211_send_cqm(msg, gfp); 14041 return; 14042 14043 nla_put_failure: 14044 nlmsg_free(msg); 14045 } 14046 EXPORT_SYMBOL(cfg80211_cqm_pktloss_notify); 14047 14048 void cfg80211_cqm_beacon_loss_notify(struct net_device *dev, gfp_t gfp) 14049 { 14050 struct sk_buff *msg; 14051 14052 msg = cfg80211_prepare_cqm(dev, NULL, gfp); 14053 if (!msg) 14054 return; 14055 14056 if (nla_put_flag(msg, NL80211_ATTR_CQM_BEACON_LOSS_EVENT)) 14057 goto nla_put_failure; 14058 14059 cfg80211_send_cqm(msg, gfp); 14060 return; 14061 14062 nla_put_failure: 14063 nlmsg_free(msg); 14064 } 14065 EXPORT_SYMBOL(cfg80211_cqm_beacon_loss_notify); 14066 14067 static void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev, 14068 struct net_device *netdev, const u8 *bssid, 14069 const u8 *replay_ctr, gfp_t gfp) 14070 { 14071 struct sk_buff *msg; 14072 struct nlattr *rekey_attr; 14073 void *hdr; 14074 14075 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14076 if (!msg) 14077 return; 14078 14079 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD); 14080 if (!hdr) { 14081 nlmsg_free(msg); 14082 return; 14083 } 14084 14085 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14086 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 14087 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) 14088 goto nla_put_failure; 14089 14090 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA); 14091 if (!rekey_attr) 14092 goto nla_put_failure; 14093 14094 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR, 14095 NL80211_REPLAY_CTR_LEN, replay_ctr)) 14096 goto nla_put_failure; 14097 14098 nla_nest_end(msg, rekey_attr); 14099 14100 genlmsg_end(msg, hdr); 14101 14102 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14103 NL80211_MCGRP_MLME, gfp); 14104 return; 14105 14106 nla_put_failure: 14107 genlmsg_cancel(msg, hdr); 14108 nlmsg_free(msg); 14109 } 14110 14111 void cfg80211_gtk_rekey_notify(struct net_device *dev, const u8 *bssid, 14112 const u8 *replay_ctr, gfp_t gfp) 14113 { 14114 struct wireless_dev *wdev = dev->ieee80211_ptr; 14115 struct wiphy *wiphy = wdev->wiphy; 14116 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14117 14118 trace_cfg80211_gtk_rekey_notify(dev, bssid); 14119 nl80211_gtk_rekey_notify(rdev, dev, bssid, replay_ctr, gfp); 14120 } 14121 EXPORT_SYMBOL(cfg80211_gtk_rekey_notify); 14122 14123 static void 14124 nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev, 14125 struct net_device *netdev, int index, 14126 const u8 *bssid, bool preauth, gfp_t gfp) 14127 { 14128 struct sk_buff *msg; 14129 struct nlattr *attr; 14130 void *hdr; 14131 14132 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14133 if (!msg) 14134 return; 14135 14136 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE); 14137 if (!hdr) { 14138 nlmsg_free(msg); 14139 return; 14140 } 14141 14142 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14143 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex)) 14144 goto nla_put_failure; 14145 14146 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE); 14147 if (!attr) 14148 goto nla_put_failure; 14149 14150 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) || 14151 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) || 14152 (preauth && 14153 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH))) 14154 goto nla_put_failure; 14155 14156 nla_nest_end(msg, attr); 14157 14158 genlmsg_end(msg, hdr); 14159 14160 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14161 NL80211_MCGRP_MLME, gfp); 14162 return; 14163 14164 nla_put_failure: 14165 genlmsg_cancel(msg, hdr); 14166 nlmsg_free(msg); 14167 } 14168 14169 void cfg80211_pmksa_candidate_notify(struct net_device *dev, int index, 14170 const u8 *bssid, bool preauth, gfp_t gfp) 14171 { 14172 struct wireless_dev *wdev = dev->ieee80211_ptr; 14173 struct wiphy *wiphy = wdev->wiphy; 14174 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14175 14176 trace_cfg80211_pmksa_candidate_notify(dev, index, bssid, preauth); 14177 nl80211_pmksa_candidate_notify(rdev, dev, index, bssid, preauth, gfp); 14178 } 14179 EXPORT_SYMBOL(cfg80211_pmksa_candidate_notify); 14180 14181 static void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev, 14182 struct net_device *netdev, 14183 struct cfg80211_chan_def *chandef, 14184 gfp_t gfp, 14185 enum nl80211_commands notif, 14186 u8 count) 14187 { 14188 struct sk_buff *msg; 14189 void *hdr; 14190 14191 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14192 if (!msg) 14193 return; 14194 14195 hdr = nl80211hdr_put(msg, 0, 0, 0, notif); 14196 if (!hdr) { 14197 nlmsg_free(msg); 14198 return; 14199 } 14200 14201 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex)) 14202 goto nla_put_failure; 14203 14204 if (nl80211_send_chandef(msg, chandef)) 14205 goto nla_put_failure; 14206 14207 if ((notif == NL80211_CMD_CH_SWITCH_STARTED_NOTIFY) && 14208 (nla_put_u32(msg, NL80211_ATTR_CH_SWITCH_COUNT, count))) 14209 goto nla_put_failure; 14210 14211 genlmsg_end(msg, hdr); 14212 14213 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14214 NL80211_MCGRP_MLME, gfp); 14215 return; 14216 14217 nla_put_failure: 14218 genlmsg_cancel(msg, hdr); 14219 nlmsg_free(msg); 14220 } 14221 14222 void cfg80211_ch_switch_notify(struct net_device *dev, 14223 struct cfg80211_chan_def *chandef) 14224 { 14225 struct wireless_dev *wdev = dev->ieee80211_ptr; 14226 struct wiphy *wiphy = wdev->wiphy; 14227 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14228 14229 ASSERT_WDEV_LOCK(wdev); 14230 14231 trace_cfg80211_ch_switch_notify(dev, chandef); 14232 14233 wdev->chandef = *chandef; 14234 wdev->preset_chandef = *chandef; 14235 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL, 14236 NL80211_CMD_CH_SWITCH_NOTIFY, 0); 14237 } 14238 EXPORT_SYMBOL(cfg80211_ch_switch_notify); 14239 14240 void cfg80211_ch_switch_started_notify(struct net_device *dev, 14241 struct cfg80211_chan_def *chandef, 14242 u8 count) 14243 { 14244 struct wireless_dev *wdev = dev->ieee80211_ptr; 14245 struct wiphy *wiphy = wdev->wiphy; 14246 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14247 14248 trace_cfg80211_ch_switch_started_notify(dev, chandef); 14249 14250 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL, 14251 NL80211_CMD_CH_SWITCH_STARTED_NOTIFY, count); 14252 } 14253 EXPORT_SYMBOL(cfg80211_ch_switch_started_notify); 14254 14255 void 14256 nl80211_radar_notify(struct cfg80211_registered_device *rdev, 14257 const struct cfg80211_chan_def *chandef, 14258 enum nl80211_radar_event event, 14259 struct net_device *netdev, gfp_t gfp) 14260 { 14261 struct sk_buff *msg; 14262 void *hdr; 14263 14264 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14265 if (!msg) 14266 return; 14267 14268 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_RADAR_DETECT); 14269 if (!hdr) { 14270 nlmsg_free(msg); 14271 return; 14272 } 14273 14274 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx)) 14275 goto nla_put_failure; 14276 14277 /* NOP and radar events don't need a netdev parameter */ 14278 if (netdev) { 14279 struct wireless_dev *wdev = netdev->ieee80211_ptr; 14280 14281 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 14282 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 14283 NL80211_ATTR_PAD)) 14284 goto nla_put_failure; 14285 } 14286 14287 if (nla_put_u32(msg, NL80211_ATTR_RADAR_EVENT, event)) 14288 goto nla_put_failure; 14289 14290 if (nl80211_send_chandef(msg, chandef)) 14291 goto nla_put_failure; 14292 14293 genlmsg_end(msg, hdr); 14294 14295 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14296 NL80211_MCGRP_MLME, gfp); 14297 return; 14298 14299 nla_put_failure: 14300 genlmsg_cancel(msg, hdr); 14301 nlmsg_free(msg); 14302 } 14303 14304 void cfg80211_probe_status(struct net_device *dev, const u8 *addr, 14305 u64 cookie, bool acked, gfp_t gfp) 14306 { 14307 struct wireless_dev *wdev = dev->ieee80211_ptr; 14308 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 14309 struct sk_buff *msg; 14310 void *hdr; 14311 14312 trace_cfg80211_probe_status(dev, addr, cookie, acked); 14313 14314 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14315 14316 if (!msg) 14317 return; 14318 14319 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT); 14320 if (!hdr) { 14321 nlmsg_free(msg); 14322 return; 14323 } 14324 14325 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14326 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 14327 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) || 14328 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 14329 NL80211_ATTR_PAD) || 14330 (acked && nla_put_flag(msg, NL80211_ATTR_ACK))) 14331 goto nla_put_failure; 14332 14333 genlmsg_end(msg, hdr); 14334 14335 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14336 NL80211_MCGRP_MLME, gfp); 14337 return; 14338 14339 nla_put_failure: 14340 genlmsg_cancel(msg, hdr); 14341 nlmsg_free(msg); 14342 } 14343 EXPORT_SYMBOL(cfg80211_probe_status); 14344 14345 void cfg80211_report_obss_beacon(struct wiphy *wiphy, 14346 const u8 *frame, size_t len, 14347 int freq, int sig_dbm) 14348 { 14349 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14350 struct sk_buff *msg; 14351 void *hdr; 14352 struct cfg80211_beacon_registration *reg; 14353 14354 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm); 14355 14356 spin_lock_bh(&rdev->beacon_registrations_lock); 14357 list_for_each_entry(reg, &rdev->beacon_registrations, list) { 14358 msg = nlmsg_new(len + 100, GFP_ATOMIC); 14359 if (!msg) { 14360 spin_unlock_bh(&rdev->beacon_registrations_lock); 14361 return; 14362 } 14363 14364 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME); 14365 if (!hdr) 14366 goto nla_put_failure; 14367 14368 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14369 (freq && 14370 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) || 14371 (sig_dbm && 14372 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) || 14373 nla_put(msg, NL80211_ATTR_FRAME, len, frame)) 14374 goto nla_put_failure; 14375 14376 genlmsg_end(msg, hdr); 14377 14378 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid); 14379 } 14380 spin_unlock_bh(&rdev->beacon_registrations_lock); 14381 return; 14382 14383 nla_put_failure: 14384 spin_unlock_bh(&rdev->beacon_registrations_lock); 14385 if (hdr) 14386 genlmsg_cancel(msg, hdr); 14387 nlmsg_free(msg); 14388 } 14389 EXPORT_SYMBOL(cfg80211_report_obss_beacon); 14390 14391 #ifdef CONFIG_PM 14392 static int cfg80211_net_detect_results(struct sk_buff *msg, 14393 struct cfg80211_wowlan_wakeup *wakeup) 14394 { 14395 struct cfg80211_wowlan_nd_info *nd = wakeup->net_detect; 14396 struct nlattr *nl_results, *nl_match, *nl_freqs; 14397 int i, j; 14398 14399 nl_results = nla_nest_start( 14400 msg, NL80211_WOWLAN_TRIG_NET_DETECT_RESULTS); 14401 if (!nl_results) 14402 return -EMSGSIZE; 14403 14404 for (i = 0; i < nd->n_matches; i++) { 14405 struct cfg80211_wowlan_nd_match *match = nd->matches[i]; 14406 14407 nl_match = nla_nest_start(msg, i); 14408 if (!nl_match) 14409 break; 14410 14411 /* The SSID attribute is optional in nl80211, but for 14412 * simplicity reasons it's always present in the 14413 * cfg80211 structure. If a driver can't pass the 14414 * SSID, that needs to be changed. A zero length SSID 14415 * is still a valid SSID (wildcard), so it cannot be 14416 * used for this purpose. 14417 */ 14418 if (nla_put(msg, NL80211_ATTR_SSID, match->ssid.ssid_len, 14419 match->ssid.ssid)) { 14420 nla_nest_cancel(msg, nl_match); 14421 goto out; 14422 } 14423 14424 if (match->n_channels) { 14425 nl_freqs = nla_nest_start( 14426 msg, NL80211_ATTR_SCAN_FREQUENCIES); 14427 if (!nl_freqs) { 14428 nla_nest_cancel(msg, nl_match); 14429 goto out; 14430 } 14431 14432 for (j = 0; j < match->n_channels; j++) { 14433 if (nla_put_u32(msg, j, match->channels[j])) { 14434 nla_nest_cancel(msg, nl_freqs); 14435 nla_nest_cancel(msg, nl_match); 14436 goto out; 14437 } 14438 } 14439 14440 nla_nest_end(msg, nl_freqs); 14441 } 14442 14443 nla_nest_end(msg, nl_match); 14444 } 14445 14446 out: 14447 nla_nest_end(msg, nl_results); 14448 return 0; 14449 } 14450 14451 void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev, 14452 struct cfg80211_wowlan_wakeup *wakeup, 14453 gfp_t gfp) 14454 { 14455 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 14456 struct sk_buff *msg; 14457 void *hdr; 14458 int size = 200; 14459 14460 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup); 14461 14462 if (wakeup) 14463 size += wakeup->packet_present_len; 14464 14465 msg = nlmsg_new(size, gfp); 14466 if (!msg) 14467 return; 14468 14469 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN); 14470 if (!hdr) 14471 goto free_msg; 14472 14473 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14474 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 14475 NL80211_ATTR_PAD)) 14476 goto free_msg; 14477 14478 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 14479 wdev->netdev->ifindex)) 14480 goto free_msg; 14481 14482 if (wakeup) { 14483 struct nlattr *reasons; 14484 14485 reasons = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS); 14486 if (!reasons) 14487 goto free_msg; 14488 14489 if (wakeup->disconnect && 14490 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) 14491 goto free_msg; 14492 if (wakeup->magic_pkt && 14493 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) 14494 goto free_msg; 14495 if (wakeup->gtk_rekey_failure && 14496 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) 14497 goto free_msg; 14498 if (wakeup->eap_identity_req && 14499 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) 14500 goto free_msg; 14501 if (wakeup->four_way_handshake && 14502 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) 14503 goto free_msg; 14504 if (wakeup->rfkill_release && 14505 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)) 14506 goto free_msg; 14507 14508 if (wakeup->pattern_idx >= 0 && 14509 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN, 14510 wakeup->pattern_idx)) 14511 goto free_msg; 14512 14513 if (wakeup->tcp_match && 14514 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_MATCH)) 14515 goto free_msg; 14516 14517 if (wakeup->tcp_connlost && 14518 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_CONNLOST)) 14519 goto free_msg; 14520 14521 if (wakeup->tcp_nomoretokens && 14522 nla_put_flag(msg, 14523 NL80211_WOWLAN_TRIG_WAKEUP_TCP_NOMORETOKENS)) 14524 goto free_msg; 14525 14526 if (wakeup->packet) { 14527 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211; 14528 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN; 14529 14530 if (!wakeup->packet_80211) { 14531 pkt_attr = 14532 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023; 14533 len_attr = 14534 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN; 14535 } 14536 14537 if (wakeup->packet_len && 14538 nla_put_u32(msg, len_attr, wakeup->packet_len)) 14539 goto free_msg; 14540 14541 if (nla_put(msg, pkt_attr, wakeup->packet_present_len, 14542 wakeup->packet)) 14543 goto free_msg; 14544 } 14545 14546 if (wakeup->net_detect && 14547 cfg80211_net_detect_results(msg, wakeup)) 14548 goto free_msg; 14549 14550 nla_nest_end(msg, reasons); 14551 } 14552 14553 genlmsg_end(msg, hdr); 14554 14555 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14556 NL80211_MCGRP_MLME, gfp); 14557 return; 14558 14559 free_msg: 14560 nlmsg_free(msg); 14561 } 14562 EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup); 14563 #endif 14564 14565 void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer, 14566 enum nl80211_tdls_operation oper, 14567 u16 reason_code, gfp_t gfp) 14568 { 14569 struct wireless_dev *wdev = dev->ieee80211_ptr; 14570 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 14571 struct sk_buff *msg; 14572 void *hdr; 14573 14574 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper, 14575 reason_code); 14576 14577 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14578 if (!msg) 14579 return; 14580 14581 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER); 14582 if (!hdr) { 14583 nlmsg_free(msg); 14584 return; 14585 } 14586 14587 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14588 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 14589 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) || 14590 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) || 14591 (reason_code > 0 && 14592 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code))) 14593 goto nla_put_failure; 14594 14595 genlmsg_end(msg, hdr); 14596 14597 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14598 NL80211_MCGRP_MLME, gfp); 14599 return; 14600 14601 nla_put_failure: 14602 genlmsg_cancel(msg, hdr); 14603 nlmsg_free(msg); 14604 } 14605 EXPORT_SYMBOL(cfg80211_tdls_oper_request); 14606 14607 static int nl80211_netlink_notify(struct notifier_block * nb, 14608 unsigned long state, 14609 void *_notify) 14610 { 14611 struct netlink_notify *notify = _notify; 14612 struct cfg80211_registered_device *rdev; 14613 struct wireless_dev *wdev; 14614 struct cfg80211_beacon_registration *reg, *tmp; 14615 14616 if (state != NETLINK_URELEASE || notify->protocol != NETLINK_GENERIC) 14617 return NOTIFY_DONE; 14618 14619 rcu_read_lock(); 14620 14621 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) { 14622 bool schedule_destroy_work = false; 14623 struct cfg80211_sched_scan_request *sched_scan_req = 14624 rcu_dereference(rdev->sched_scan_req); 14625 14626 if (sched_scan_req && notify->portid && 14627 sched_scan_req->owner_nlportid == notify->portid) { 14628 sched_scan_req->owner_nlportid = 0; 14629 14630 if (rdev->ops->sched_scan_stop && 14631 rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) 14632 schedule_work(&rdev->sched_scan_stop_wk); 14633 } 14634 14635 list_for_each_entry_rcu(wdev, &rdev->wiphy.wdev_list, list) { 14636 cfg80211_mlme_unregister_socket(wdev, notify->portid); 14637 14638 if (wdev->owner_nlportid == notify->portid) 14639 schedule_destroy_work = true; 14640 else if (wdev->conn_owner_nlportid == notify->portid) 14641 schedule_work(&wdev->disconnect_wk); 14642 } 14643 14644 spin_lock_bh(&rdev->beacon_registrations_lock); 14645 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations, 14646 list) { 14647 if (reg->nlportid == notify->portid) { 14648 list_del(®->list); 14649 kfree(reg); 14650 break; 14651 } 14652 } 14653 spin_unlock_bh(&rdev->beacon_registrations_lock); 14654 14655 if (schedule_destroy_work) { 14656 struct cfg80211_iface_destroy *destroy; 14657 14658 destroy = kzalloc(sizeof(*destroy), GFP_ATOMIC); 14659 if (destroy) { 14660 destroy->nlportid = notify->portid; 14661 spin_lock(&rdev->destroy_list_lock); 14662 list_add(&destroy->list, &rdev->destroy_list); 14663 spin_unlock(&rdev->destroy_list_lock); 14664 schedule_work(&rdev->destroy_work); 14665 } 14666 } 14667 } 14668 14669 rcu_read_unlock(); 14670 14671 /* 14672 * It is possible that the user space process that is controlling the 14673 * indoor setting disappeared, so notify the regulatory core. 14674 */ 14675 regulatory_netlink_notify(notify->portid); 14676 return NOTIFY_OK; 14677 } 14678 14679 static struct notifier_block nl80211_netlink_notifier = { 14680 .notifier_call = nl80211_netlink_notify, 14681 }; 14682 14683 void cfg80211_ft_event(struct net_device *netdev, 14684 struct cfg80211_ft_event_params *ft_event) 14685 { 14686 struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy; 14687 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14688 struct sk_buff *msg; 14689 void *hdr; 14690 14691 trace_cfg80211_ft_event(wiphy, netdev, ft_event); 14692 14693 if (!ft_event->target_ap) 14694 return; 14695 14696 msg = nlmsg_new(100 + ft_event->ric_ies_len, GFP_KERNEL); 14697 if (!msg) 14698 return; 14699 14700 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FT_EVENT); 14701 if (!hdr) 14702 goto out; 14703 14704 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14705 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 14706 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, ft_event->target_ap)) 14707 goto out; 14708 14709 if (ft_event->ies && 14710 nla_put(msg, NL80211_ATTR_IE, ft_event->ies_len, ft_event->ies)) 14711 goto out; 14712 if (ft_event->ric_ies && 14713 nla_put(msg, NL80211_ATTR_IE_RIC, ft_event->ric_ies_len, 14714 ft_event->ric_ies)) 14715 goto out; 14716 14717 genlmsg_end(msg, hdr); 14718 14719 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14720 NL80211_MCGRP_MLME, GFP_KERNEL); 14721 return; 14722 out: 14723 nlmsg_free(msg); 14724 } 14725 EXPORT_SYMBOL(cfg80211_ft_event); 14726 14727 void cfg80211_crit_proto_stopped(struct wireless_dev *wdev, gfp_t gfp) 14728 { 14729 struct cfg80211_registered_device *rdev; 14730 struct sk_buff *msg; 14731 void *hdr; 14732 u32 nlportid; 14733 14734 rdev = wiphy_to_rdev(wdev->wiphy); 14735 if (!rdev->crit_proto_nlportid) 14736 return; 14737 14738 nlportid = rdev->crit_proto_nlportid; 14739 rdev->crit_proto_nlportid = 0; 14740 14741 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14742 if (!msg) 14743 return; 14744 14745 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CRIT_PROTOCOL_STOP); 14746 if (!hdr) 14747 goto nla_put_failure; 14748 14749 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14750 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 14751 NL80211_ATTR_PAD)) 14752 goto nla_put_failure; 14753 14754 genlmsg_end(msg, hdr); 14755 14756 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid); 14757 return; 14758 14759 nla_put_failure: 14760 if (hdr) 14761 genlmsg_cancel(msg, hdr); 14762 nlmsg_free(msg); 14763 } 14764 EXPORT_SYMBOL(cfg80211_crit_proto_stopped); 14765 14766 void nl80211_send_ap_stopped(struct wireless_dev *wdev) 14767 { 14768 struct wiphy *wiphy = wdev->wiphy; 14769 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14770 struct sk_buff *msg; 14771 void *hdr; 14772 14773 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 14774 if (!msg) 14775 return; 14776 14777 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_STOP_AP); 14778 if (!hdr) 14779 goto out; 14780 14781 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14782 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex) || 14783 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 14784 NL80211_ATTR_PAD)) 14785 goto out; 14786 14787 genlmsg_end(msg, hdr); 14788 14789 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(wiphy), msg, 0, 14790 NL80211_MCGRP_MLME, GFP_KERNEL); 14791 return; 14792 out: 14793 nlmsg_free(msg); 14794 } 14795 14796 /* initialisation/exit functions */ 14797 14798 int __init nl80211_init(void) 14799 { 14800 int err; 14801 14802 err = genl_register_family(&nl80211_fam); 14803 if (err) 14804 return err; 14805 14806 err = netlink_register_notifier(&nl80211_netlink_notifier); 14807 if (err) 14808 goto err_out; 14809 14810 return 0; 14811 err_out: 14812 genl_unregister_family(&nl80211_fam); 14813 return err; 14814 } 14815 14816 void nl80211_exit(void) 14817 { 14818 netlink_unregister_notifier(&nl80211_netlink_notifier); 14819 genl_unregister_family(&nl80211_fam); 14820 } 14821