xref: /openbmc/linux/net/wireless/nl80211.c (revision 8ebc80a25f9d9bf7a8e368b266d5b740c485c362)
1 // SPDX-License-Identifier: GPL-2.0-only
2 /*
3  * This is the new netlink-based wireless configuration interface.
4  *
5  * Copyright 2006-2010	Johannes Berg <johannes@sipsolutions.net>
6  * Copyright 2013-2014  Intel Mobile Communications GmbH
7  * Copyright 2015-2017	Intel Deutschland GmbH
8  * Copyright (C) 2018-2023 Intel Corporation
9  */
10 
11 #include <linux/if.h>
12 #include <linux/module.h>
13 #include <linux/err.h>
14 #include <linux/slab.h>
15 #include <linux/list.h>
16 #include <linux/if_ether.h>
17 #include <linux/ieee80211.h>
18 #include <linux/nl80211.h>
19 #include <linux/rtnetlink.h>
20 #include <linux/netlink.h>
21 #include <linux/nospec.h>
22 #include <linux/etherdevice.h>
23 #include <linux/if_vlan.h>
24 #include <net/net_namespace.h>
25 #include <net/genetlink.h>
26 #include <net/cfg80211.h>
27 #include <net/sock.h>
28 #include <net/inet_connection_sock.h>
29 #include "core.h"
30 #include "nl80211.h"
31 #include "reg.h"
32 #include "rdev-ops.h"
33 
34 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
35 				   struct genl_info *info,
36 				   struct cfg80211_crypto_settings *settings,
37 				   int cipher_limit);
38 
39 /* the netlink family */
40 static struct genl_family nl80211_fam;
41 
42 /* multicast groups */
43 enum nl80211_multicast_groups {
44 	NL80211_MCGRP_CONFIG,
45 	NL80211_MCGRP_SCAN,
46 	NL80211_MCGRP_REGULATORY,
47 	NL80211_MCGRP_MLME,
48 	NL80211_MCGRP_VENDOR,
49 	NL80211_MCGRP_NAN,
50 	NL80211_MCGRP_TESTMODE /* keep last - ifdef! */
51 };
52 
53 static const struct genl_multicast_group nl80211_mcgrps[] = {
54 	[NL80211_MCGRP_CONFIG] = { .name = NL80211_MULTICAST_GROUP_CONFIG },
55 	[NL80211_MCGRP_SCAN] = { .name = NL80211_MULTICAST_GROUP_SCAN },
56 	[NL80211_MCGRP_REGULATORY] = { .name = NL80211_MULTICAST_GROUP_REG },
57 	[NL80211_MCGRP_MLME] = { .name = NL80211_MULTICAST_GROUP_MLME },
58 	[NL80211_MCGRP_VENDOR] = { .name = NL80211_MULTICAST_GROUP_VENDOR },
59 	[NL80211_MCGRP_NAN] = { .name = NL80211_MULTICAST_GROUP_NAN },
60 #ifdef CONFIG_NL80211_TESTMODE
61 	[NL80211_MCGRP_TESTMODE] = { .name = NL80211_MULTICAST_GROUP_TESTMODE }
62 #endif
63 };
64 
65 /* returns ERR_PTR values */
66 static struct wireless_dev *
__cfg80211_wdev_from_attrs(struct cfg80211_registered_device * rdev,struct net * netns,struct nlattr ** attrs)67 __cfg80211_wdev_from_attrs(struct cfg80211_registered_device *rdev,
68 			   struct net *netns, struct nlattr **attrs)
69 {
70 	struct wireless_dev *result = NULL;
71 	bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
72 	bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
73 	u64 wdev_id = 0;
74 	int wiphy_idx = -1;
75 	int ifidx = -1;
76 
77 	if (!have_ifidx && !have_wdev_id)
78 		return ERR_PTR(-EINVAL);
79 
80 	if (have_ifidx)
81 		ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
82 	if (have_wdev_id) {
83 		wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
84 		wiphy_idx = wdev_id >> 32;
85 	}
86 
87 	if (rdev) {
88 		struct wireless_dev *wdev;
89 
90 		lockdep_assert_held(&rdev->wiphy.mtx);
91 
92 		list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
93 			if (have_ifidx && wdev->netdev &&
94 			    wdev->netdev->ifindex == ifidx) {
95 				result = wdev;
96 				break;
97 			}
98 			if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
99 				result = wdev;
100 				break;
101 			}
102 		}
103 
104 		return result ?: ERR_PTR(-ENODEV);
105 	}
106 
107 	ASSERT_RTNL();
108 
109 	list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
110 		struct wireless_dev *wdev;
111 
112 		if (wiphy_net(&rdev->wiphy) != netns)
113 			continue;
114 
115 		if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
116 			continue;
117 
118 		list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
119 			if (have_ifidx && wdev->netdev &&
120 			    wdev->netdev->ifindex == ifidx) {
121 				result = wdev;
122 				break;
123 			}
124 			if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
125 				result = wdev;
126 				break;
127 			}
128 		}
129 
130 		if (result)
131 			break;
132 	}
133 
134 	if (result)
135 		return result;
136 	return ERR_PTR(-ENODEV);
137 }
138 
139 static struct cfg80211_registered_device *
__cfg80211_rdev_from_attrs(struct net * netns,struct nlattr ** attrs)140 __cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
141 {
142 	struct cfg80211_registered_device *rdev = NULL, *tmp;
143 	struct net_device *netdev;
144 
145 	ASSERT_RTNL();
146 
147 	if (!attrs[NL80211_ATTR_WIPHY] &&
148 	    !attrs[NL80211_ATTR_IFINDEX] &&
149 	    !attrs[NL80211_ATTR_WDEV])
150 		return ERR_PTR(-EINVAL);
151 
152 	if (attrs[NL80211_ATTR_WIPHY])
153 		rdev = cfg80211_rdev_by_wiphy_idx(
154 				nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
155 
156 	if (attrs[NL80211_ATTR_WDEV]) {
157 		u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
158 		struct wireless_dev *wdev;
159 		bool found = false;
160 
161 		tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
162 		if (tmp) {
163 			/* make sure wdev exists */
164 			list_for_each_entry(wdev, &tmp->wiphy.wdev_list, list) {
165 				if (wdev->identifier != (u32)wdev_id)
166 					continue;
167 				found = true;
168 				break;
169 			}
170 
171 			if (!found)
172 				tmp = NULL;
173 
174 			if (rdev && tmp != rdev)
175 				return ERR_PTR(-EINVAL);
176 			rdev = tmp;
177 		}
178 	}
179 
180 	if (attrs[NL80211_ATTR_IFINDEX]) {
181 		int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
182 
183 		netdev = __dev_get_by_index(netns, ifindex);
184 		if (netdev) {
185 			if (netdev->ieee80211_ptr)
186 				tmp = wiphy_to_rdev(
187 					netdev->ieee80211_ptr->wiphy);
188 			else
189 				tmp = NULL;
190 
191 			/* not wireless device -- return error */
192 			if (!tmp)
193 				return ERR_PTR(-EINVAL);
194 
195 			/* mismatch -- return error */
196 			if (rdev && tmp != rdev)
197 				return ERR_PTR(-EINVAL);
198 
199 			rdev = tmp;
200 		}
201 	}
202 
203 	if (!rdev)
204 		return ERR_PTR(-ENODEV);
205 
206 	if (netns != wiphy_net(&rdev->wiphy))
207 		return ERR_PTR(-ENODEV);
208 
209 	return rdev;
210 }
211 
212 /*
213  * This function returns a pointer to the driver
214  * that the genl_info item that is passed refers to.
215  *
216  * The result of this can be a PTR_ERR and hence must
217  * be checked with IS_ERR() for errors.
218  */
219 static struct cfg80211_registered_device *
cfg80211_get_dev_from_info(struct net * netns,struct genl_info * info)220 cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
221 {
222 	return __cfg80211_rdev_from_attrs(netns, info->attrs);
223 }
224 
validate_beacon_head(const struct nlattr * attr,struct netlink_ext_ack * extack)225 static int validate_beacon_head(const struct nlattr *attr,
226 				struct netlink_ext_ack *extack)
227 {
228 	const u8 *data = nla_data(attr);
229 	unsigned int len = nla_len(attr);
230 	const struct element *elem;
231 	const struct ieee80211_mgmt *mgmt = (void *)data;
232 	unsigned int fixedlen, hdrlen;
233 	bool s1g_bcn;
234 
235 	if (len < offsetofend(typeof(*mgmt), frame_control))
236 		goto err;
237 
238 	s1g_bcn = ieee80211_is_s1g_beacon(mgmt->frame_control);
239 	if (s1g_bcn) {
240 		fixedlen = offsetof(struct ieee80211_ext,
241 				    u.s1g_beacon.variable);
242 		hdrlen = offsetof(struct ieee80211_ext, u.s1g_beacon);
243 	} else {
244 		fixedlen = offsetof(struct ieee80211_mgmt,
245 				    u.beacon.variable);
246 		hdrlen = offsetof(struct ieee80211_mgmt, u.beacon);
247 	}
248 
249 	if (len < fixedlen)
250 		goto err;
251 
252 	if (ieee80211_hdrlen(mgmt->frame_control) != hdrlen)
253 		goto err;
254 
255 	data += fixedlen;
256 	len -= fixedlen;
257 
258 	for_each_element(elem, data, len) {
259 		/* nothing */
260 	}
261 
262 	if (for_each_element_completed(elem, data, len))
263 		return 0;
264 
265 err:
266 	NL_SET_ERR_MSG_ATTR(extack, attr, "malformed beacon head");
267 	return -EINVAL;
268 }
269 
validate_ie_attr(const struct nlattr * attr,struct netlink_ext_ack * extack)270 static int validate_ie_attr(const struct nlattr *attr,
271 			    struct netlink_ext_ack *extack)
272 {
273 	const u8 *data = nla_data(attr);
274 	unsigned int len = nla_len(attr);
275 	const struct element *elem;
276 
277 	for_each_element(elem, data, len) {
278 		/* nothing */
279 	}
280 
281 	if (for_each_element_completed(elem, data, len))
282 		return 0;
283 
284 	NL_SET_ERR_MSG_ATTR(extack, attr, "malformed information elements");
285 	return -EINVAL;
286 }
287 
validate_he_capa(const struct nlattr * attr,struct netlink_ext_ack * extack)288 static int validate_he_capa(const struct nlattr *attr,
289 			    struct netlink_ext_ack *extack)
290 {
291 	if (!ieee80211_he_capa_size_ok(nla_data(attr), nla_len(attr)))
292 		return -EINVAL;
293 
294 	return 0;
295 }
296 
297 /* policy for the attributes */
298 static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR];
299 
300 static const struct nla_policy
301 nl80211_ftm_responder_policy[NL80211_FTM_RESP_ATTR_MAX + 1] = {
302 	[NL80211_FTM_RESP_ATTR_ENABLED] = { .type = NLA_FLAG, },
303 	[NL80211_FTM_RESP_ATTR_LCI] = { .type = NLA_BINARY,
304 					.len = U8_MAX },
305 	[NL80211_FTM_RESP_ATTR_CIVICLOC] = { .type = NLA_BINARY,
306 					     .len = U8_MAX },
307 };
308 
309 static const struct nla_policy
310 nl80211_pmsr_ftm_req_attr_policy[NL80211_PMSR_FTM_REQ_ATTR_MAX + 1] = {
311 	[NL80211_PMSR_FTM_REQ_ATTR_ASAP] = { .type = NLA_FLAG },
312 	[NL80211_PMSR_FTM_REQ_ATTR_PREAMBLE] = { .type = NLA_U32 },
313 	[NL80211_PMSR_FTM_REQ_ATTR_NUM_BURSTS_EXP] =
314 		NLA_POLICY_MAX(NLA_U8, 15),
315 	[NL80211_PMSR_FTM_REQ_ATTR_BURST_PERIOD] = { .type = NLA_U16 },
316 	[NL80211_PMSR_FTM_REQ_ATTR_BURST_DURATION] =
317 		NLA_POLICY_MAX(NLA_U8, 15),
318 	[NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST] =
319 		NLA_POLICY_MAX(NLA_U8, 31),
320 	[NL80211_PMSR_FTM_REQ_ATTR_NUM_FTMR_RETRIES] = { .type = NLA_U8 },
321 	[NL80211_PMSR_FTM_REQ_ATTR_REQUEST_LCI] = { .type = NLA_FLAG },
322 	[NL80211_PMSR_FTM_REQ_ATTR_REQUEST_CIVICLOC] = { .type = NLA_FLAG },
323 	[NL80211_PMSR_FTM_REQ_ATTR_TRIGGER_BASED] = { .type = NLA_FLAG },
324 	[NL80211_PMSR_FTM_REQ_ATTR_NON_TRIGGER_BASED] = { .type = NLA_FLAG },
325 	[NL80211_PMSR_FTM_REQ_ATTR_LMR_FEEDBACK] = { .type = NLA_FLAG },
326 	[NL80211_PMSR_FTM_REQ_ATTR_BSS_COLOR] = { .type = NLA_U8 },
327 };
328 
329 static const struct nla_policy
330 nl80211_pmsr_req_data_policy[NL80211_PMSR_TYPE_MAX + 1] = {
331 	[NL80211_PMSR_TYPE_FTM] =
332 		NLA_POLICY_NESTED(nl80211_pmsr_ftm_req_attr_policy),
333 };
334 
335 static const struct nla_policy
336 nl80211_pmsr_req_attr_policy[NL80211_PMSR_REQ_ATTR_MAX + 1] = {
337 	[NL80211_PMSR_REQ_ATTR_DATA] =
338 		NLA_POLICY_NESTED(nl80211_pmsr_req_data_policy),
339 	[NL80211_PMSR_REQ_ATTR_GET_AP_TSF] = { .type = NLA_FLAG },
340 };
341 
342 static const struct nla_policy
343 nl80211_pmsr_peer_attr_policy[NL80211_PMSR_PEER_ATTR_MAX + 1] = {
344 	[NL80211_PMSR_PEER_ATTR_ADDR] = NLA_POLICY_ETH_ADDR,
345 	[NL80211_PMSR_PEER_ATTR_CHAN] = NLA_POLICY_NESTED(nl80211_policy),
346 	[NL80211_PMSR_PEER_ATTR_REQ] =
347 		NLA_POLICY_NESTED(nl80211_pmsr_req_attr_policy),
348 	[NL80211_PMSR_PEER_ATTR_RESP] = { .type = NLA_REJECT },
349 };
350 
351 static const struct nla_policy
352 nl80211_pmsr_attr_policy[NL80211_PMSR_ATTR_MAX + 1] = {
353 	[NL80211_PMSR_ATTR_MAX_PEERS] = { .type = NLA_REJECT },
354 	[NL80211_PMSR_ATTR_REPORT_AP_TSF] = { .type = NLA_REJECT },
355 	[NL80211_PMSR_ATTR_RANDOMIZE_MAC_ADDR] = { .type = NLA_REJECT },
356 	[NL80211_PMSR_ATTR_TYPE_CAPA] = { .type = NLA_REJECT },
357 	[NL80211_PMSR_ATTR_PEERS] =
358 		NLA_POLICY_NESTED_ARRAY(nl80211_pmsr_peer_attr_policy),
359 };
360 
361 static const struct nla_policy
362 he_obss_pd_policy[NL80211_HE_OBSS_PD_ATTR_MAX + 1] = {
363 	[NL80211_HE_OBSS_PD_ATTR_MIN_OFFSET] =
364 		NLA_POLICY_RANGE(NLA_U8, 1, 20),
365 	[NL80211_HE_OBSS_PD_ATTR_MAX_OFFSET] =
366 		NLA_POLICY_RANGE(NLA_U8, 1, 20),
367 	[NL80211_HE_OBSS_PD_ATTR_NON_SRG_MAX_OFFSET] =
368 		NLA_POLICY_RANGE(NLA_U8, 1, 20),
369 	[NL80211_HE_OBSS_PD_ATTR_BSS_COLOR_BITMAP] =
370 		NLA_POLICY_EXACT_LEN(8),
371 	[NL80211_HE_OBSS_PD_ATTR_PARTIAL_BSSID_BITMAP] =
372 		NLA_POLICY_EXACT_LEN(8),
373 	[NL80211_HE_OBSS_PD_ATTR_SR_CTRL] = { .type = NLA_U8 },
374 };
375 
376 static const struct nla_policy
377 he_bss_color_policy[NL80211_HE_BSS_COLOR_ATTR_MAX + 1] = {
378 	[NL80211_HE_BSS_COLOR_ATTR_COLOR] = NLA_POLICY_RANGE(NLA_U8, 1, 63),
379 	[NL80211_HE_BSS_COLOR_ATTR_DISABLED] = { .type = NLA_FLAG },
380 	[NL80211_HE_BSS_COLOR_ATTR_PARTIAL] = { .type = NLA_FLAG },
381 };
382 
383 static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
384 	[NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
385 				    .len = NL80211_MAX_SUPP_RATES },
386 	[NL80211_TXRATE_HT] = { .type = NLA_BINARY,
387 				.len = NL80211_MAX_SUPP_HT_RATES },
388 	[NL80211_TXRATE_VHT] = NLA_POLICY_EXACT_LEN_WARN(sizeof(struct nl80211_txrate_vht)),
389 	[NL80211_TXRATE_GI] = { .type = NLA_U8 },
390 	[NL80211_TXRATE_HE] = NLA_POLICY_EXACT_LEN(sizeof(struct nl80211_txrate_he)),
391 	[NL80211_TXRATE_HE_GI] =  NLA_POLICY_RANGE(NLA_U8,
392 						   NL80211_RATE_INFO_HE_GI_0_8,
393 						   NL80211_RATE_INFO_HE_GI_3_2),
394 	[NL80211_TXRATE_HE_LTF] = NLA_POLICY_RANGE(NLA_U8,
395 						   NL80211_RATE_INFO_HE_1XLTF,
396 						   NL80211_RATE_INFO_HE_4XLTF),
397 };
398 
399 static const struct nla_policy
400 nl80211_tid_config_attr_policy[NL80211_TID_CONFIG_ATTR_MAX + 1] = {
401 	[NL80211_TID_CONFIG_ATTR_VIF_SUPP] = { .type = NLA_U64 },
402 	[NL80211_TID_CONFIG_ATTR_PEER_SUPP] = { .type = NLA_U64 },
403 	[NL80211_TID_CONFIG_ATTR_OVERRIDE] = { .type = NLA_FLAG },
404 	[NL80211_TID_CONFIG_ATTR_TIDS] = NLA_POLICY_RANGE(NLA_U16, 1, 0xff),
405 	[NL80211_TID_CONFIG_ATTR_NOACK] =
406 			NLA_POLICY_MAX(NLA_U8, NL80211_TID_CONFIG_DISABLE),
407 	[NL80211_TID_CONFIG_ATTR_RETRY_SHORT] = NLA_POLICY_MIN(NLA_U8, 1),
408 	[NL80211_TID_CONFIG_ATTR_RETRY_LONG] = NLA_POLICY_MIN(NLA_U8, 1),
409 	[NL80211_TID_CONFIG_ATTR_AMPDU_CTRL] =
410 			NLA_POLICY_MAX(NLA_U8, NL80211_TID_CONFIG_DISABLE),
411 	[NL80211_TID_CONFIG_ATTR_RTSCTS_CTRL] =
412 			NLA_POLICY_MAX(NLA_U8, NL80211_TID_CONFIG_DISABLE),
413 	[NL80211_TID_CONFIG_ATTR_AMSDU_CTRL] =
414 			NLA_POLICY_MAX(NLA_U8, NL80211_TID_CONFIG_DISABLE),
415 	[NL80211_TID_CONFIG_ATTR_TX_RATE_TYPE] =
416 			NLA_POLICY_MAX(NLA_U8, NL80211_TX_RATE_FIXED),
417 	[NL80211_TID_CONFIG_ATTR_TX_RATE] =
418 			NLA_POLICY_NESTED(nl80211_txattr_policy),
419 };
420 
421 static const struct nla_policy
422 nl80211_fils_discovery_policy[NL80211_FILS_DISCOVERY_ATTR_MAX + 1] = {
423 	[NL80211_FILS_DISCOVERY_ATTR_INT_MIN] = NLA_POLICY_MAX(NLA_U32, 10000),
424 	[NL80211_FILS_DISCOVERY_ATTR_INT_MAX] = NLA_POLICY_MAX(NLA_U32, 10000),
425 	[NL80211_FILS_DISCOVERY_ATTR_TMPL] =
426 			NLA_POLICY_RANGE(NLA_BINARY,
427 					 NL80211_FILS_DISCOVERY_TMPL_MIN_LEN,
428 					 IEEE80211_MAX_DATA_LEN),
429 };
430 
431 static const struct nla_policy
432 nl80211_unsol_bcast_probe_resp_policy[NL80211_UNSOL_BCAST_PROBE_RESP_ATTR_MAX + 1] = {
433 	[NL80211_UNSOL_BCAST_PROBE_RESP_ATTR_INT] = NLA_POLICY_MAX(NLA_U32, 20),
434 	[NL80211_UNSOL_BCAST_PROBE_RESP_ATTR_TMPL] = { .type = NLA_BINARY,
435 						       .len = IEEE80211_MAX_DATA_LEN }
436 };
437 
438 static const struct nla_policy
439 sar_specs_policy[NL80211_SAR_ATTR_SPECS_MAX + 1] = {
440 	[NL80211_SAR_ATTR_SPECS_POWER] = { .type = NLA_S32 },
441 	[NL80211_SAR_ATTR_SPECS_RANGE_INDEX] = {.type = NLA_U32 },
442 };
443 
444 static const struct nla_policy
445 sar_policy[NL80211_SAR_ATTR_MAX + 1] = {
446 	[NL80211_SAR_ATTR_TYPE] = NLA_POLICY_MAX(NLA_U32, NUM_NL80211_SAR_TYPE),
447 	[NL80211_SAR_ATTR_SPECS] = NLA_POLICY_NESTED_ARRAY(sar_specs_policy),
448 };
449 
450 static const struct nla_policy
451 nl80211_mbssid_config_policy[NL80211_MBSSID_CONFIG_ATTR_MAX + 1] = {
452 	[NL80211_MBSSID_CONFIG_ATTR_MAX_INTERFACES] = NLA_POLICY_MIN(NLA_U8, 2),
453 	[NL80211_MBSSID_CONFIG_ATTR_MAX_EMA_PROFILE_PERIODICITY] =
454 						NLA_POLICY_MIN(NLA_U8, 1),
455 	[NL80211_MBSSID_CONFIG_ATTR_INDEX] = { .type = NLA_U8 },
456 	[NL80211_MBSSID_CONFIG_ATTR_TX_IFINDEX] = { .type = NLA_U32 },
457 	[NL80211_MBSSID_CONFIG_ATTR_EMA] = { .type = NLA_FLAG },
458 };
459 
460 static const struct nla_policy
461 nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] = {
462 	[NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
463 	[NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
464 };
465 
466 static struct netlink_range_validation nl80211_punct_bitmap_range = {
467 	.min = 0,
468 	.max = 0xffff,
469 };
470 
471 static struct netlink_range_validation q_range = {
472 	.max = INT_MAX,
473 };
474 
475 static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = {
476 	[0] = { .strict_start_type = NL80211_ATTR_HE_OBSS_PD },
477 	[NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
478 	[NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
479 				      .len = 20-1 },
480 	[NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
481 
482 	[NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
483 	[NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
484 	[NL80211_ATTR_WIPHY_EDMG_CHANNELS] = NLA_POLICY_RANGE(NLA_U8,
485 						NL80211_EDMG_CHANNELS_MIN,
486 						NL80211_EDMG_CHANNELS_MAX),
487 	[NL80211_ATTR_WIPHY_EDMG_BW_CONFIG] = NLA_POLICY_RANGE(NLA_U8,
488 						NL80211_EDMG_BW_CONFIG_MIN,
489 						NL80211_EDMG_BW_CONFIG_MAX),
490 
491 	[NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
492 	[NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
493 	[NL80211_ATTR_CENTER_FREQ1_OFFSET] = NLA_POLICY_RANGE(NLA_U32, 0, 999),
494 	[NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
495 
496 	[NL80211_ATTR_WIPHY_RETRY_SHORT] = NLA_POLICY_MIN(NLA_U8, 1),
497 	[NL80211_ATTR_WIPHY_RETRY_LONG] = NLA_POLICY_MIN(NLA_U8, 1),
498 	[NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
499 	[NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
500 	[NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
501 	[NL80211_ATTR_WIPHY_DYN_ACK] = { .type = NLA_FLAG },
502 
503 	[NL80211_ATTR_IFTYPE] = NLA_POLICY_MAX(NLA_U32, NL80211_IFTYPE_MAX),
504 	[NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
505 	[NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
506 
507 	[NL80211_ATTR_MAC] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
508 	[NL80211_ATTR_PREV_BSSID] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
509 
510 	[NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
511 	[NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
512 				    .len = WLAN_MAX_KEY_LEN },
513 	[NL80211_ATTR_KEY_IDX] = NLA_POLICY_MAX(NLA_U8, 7),
514 	[NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
515 	[NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
516 	[NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
517 	[NL80211_ATTR_KEY_TYPE] =
518 		NLA_POLICY_MAX(NLA_U32, NUM_NL80211_KEYTYPES),
519 
520 	[NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
521 	[NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
522 	[NL80211_ATTR_BEACON_HEAD] =
523 		NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_beacon_head,
524 				       IEEE80211_MAX_DATA_LEN),
525 	[NL80211_ATTR_BEACON_TAIL] =
526 		NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_ie_attr,
527 				       IEEE80211_MAX_DATA_LEN),
528 	[NL80211_ATTR_STA_AID] =
529 		NLA_POLICY_RANGE(NLA_U16, 1, IEEE80211_MAX_AID),
530 	[NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
531 	[NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
532 	[NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
533 					       .len = NL80211_MAX_SUPP_RATES },
534 	[NL80211_ATTR_STA_PLINK_ACTION] =
535 		NLA_POLICY_MAX(NLA_U8, NUM_NL80211_PLINK_ACTIONS - 1),
536 	[NL80211_ATTR_STA_TX_POWER_SETTING] =
537 		NLA_POLICY_RANGE(NLA_U8,
538 				 NL80211_TX_POWER_AUTOMATIC,
539 				 NL80211_TX_POWER_FIXED),
540 	[NL80211_ATTR_STA_TX_POWER] = { .type = NLA_S16 },
541 	[NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
542 	[NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
543 	[NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
544 				   .len = IEEE80211_MAX_MESH_ID_LEN },
545 	[NL80211_ATTR_MPATH_NEXT_HOP] = NLA_POLICY_ETH_ADDR_COMPAT,
546 
547 	/* allow 3 for NUL-termination, we used to declare this NLA_STRING */
548 	[NL80211_ATTR_REG_ALPHA2] = NLA_POLICY_RANGE(NLA_BINARY, 2, 3),
549 	[NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
550 
551 	[NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
552 	[NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
553 	[NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
554 	[NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
555 					   .len = NL80211_MAX_SUPP_RATES },
556 	[NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
557 
558 	[NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
559 	[NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
560 
561 	[NL80211_ATTR_HT_CAPABILITY] = NLA_POLICY_EXACT_LEN_WARN(NL80211_HT_CAPABILITY_LEN),
562 
563 	[NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
564 	[NL80211_ATTR_IE] = NLA_POLICY_VALIDATE_FN(NLA_BINARY,
565 						   validate_ie_attr,
566 						   IEEE80211_MAX_DATA_LEN),
567 	[NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
568 	[NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
569 
570 	[NL80211_ATTR_SSID] = { .type = NLA_BINARY,
571 				.len = IEEE80211_MAX_SSID_LEN },
572 	[NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
573 	[NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
574 	[NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
575 	[NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
576 	[NL80211_ATTR_USE_MFP] = NLA_POLICY_RANGE(NLA_U32,
577 						  NL80211_MFP_NO,
578 						  NL80211_MFP_OPTIONAL),
579 	[NL80211_ATTR_STA_FLAGS2] =
580 		NLA_POLICY_EXACT_LEN_WARN(sizeof(struct nl80211_sta_flag_update)),
581 	[NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
582 	[NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
583 	[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
584 	[NL80211_ATTR_CONTROL_PORT_OVER_NL80211] = { .type = NLA_FLAG },
585 	[NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
586 	[NL80211_ATTR_STATUS_CODE] = { .type = NLA_U16 },
587 	[NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
588 	[NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
589 	[NL80211_ATTR_PID] = { .type = NLA_U32 },
590 	[NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
591 	[NL80211_ATTR_PMKID] = NLA_POLICY_EXACT_LEN_WARN(WLAN_PMKID_LEN),
592 	[NL80211_ATTR_DURATION] = { .type = NLA_U32 },
593 	[NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
594 	[NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
595 	[NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
596 				 .len = IEEE80211_MAX_DATA_LEN },
597 	[NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
598 	[NL80211_ATTR_PS_STATE] = NLA_POLICY_RANGE(NLA_U32,
599 						   NL80211_PS_DISABLED,
600 						   NL80211_PS_ENABLED),
601 	[NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
602 	[NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
603 	[NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
604 	[NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
605 	[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
606 	[NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
607 	[NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
608 	[NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
609 	[NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
610 	[NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
611 	[NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
612 	[NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
613 	[NL80211_ATTR_STA_PLINK_STATE] =
614 		NLA_POLICY_MAX(NLA_U8, NUM_NL80211_PLINK_STATES - 1),
615 	[NL80211_ATTR_MEASUREMENT_DURATION] = { .type = NLA_U16 },
616 	[NL80211_ATTR_MEASUREMENT_DURATION_MANDATORY] = { .type = NLA_FLAG },
617 	[NL80211_ATTR_MESH_PEER_AID] =
618 		NLA_POLICY_RANGE(NLA_U16, 1, IEEE80211_MAX_AID),
619 	[NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
620 	[NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
621 	[NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
622 	[NL80211_ATTR_HIDDEN_SSID] =
623 		NLA_POLICY_RANGE(NLA_U32,
624 				 NL80211_HIDDEN_SSID_NOT_IN_USE,
625 				 NL80211_HIDDEN_SSID_ZERO_CONTENTS),
626 	[NL80211_ATTR_IE_PROBE_RESP] =
627 		NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_ie_attr,
628 				       IEEE80211_MAX_DATA_LEN),
629 	[NL80211_ATTR_IE_ASSOC_RESP] =
630 		NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_ie_attr,
631 				       IEEE80211_MAX_DATA_LEN),
632 	[NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
633 	[NL80211_ATTR_STA_WME] = NLA_POLICY_NESTED(nl80211_sta_wme_policy),
634 	[NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
635 	[NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
636 	[NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
637 	[NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
638 	[NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
639 	[NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
640 	[NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
641 	[NL80211_ATTR_TDLS_INITIATOR] = { .type = NLA_FLAG },
642 	[NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
643 	[NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
644 				      .len = IEEE80211_MAX_DATA_LEN },
645 	[NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
646 	[NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
647 	[NL80211_ATTR_HT_CAPABILITY_MASK] = {
648 		.len = NL80211_HT_CAPABILITY_LEN
649 	},
650 	[NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
651 	[NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
652 	[NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
653 	[NL80211_ATTR_WDEV] = { .type = NLA_U64 },
654 	[NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
655 
656 	/* need to include at least Auth Transaction and Status Code */
657 	[NL80211_ATTR_AUTH_DATA] = NLA_POLICY_MIN_LEN(4),
658 
659 	[NL80211_ATTR_VHT_CAPABILITY] = NLA_POLICY_EXACT_LEN_WARN(NL80211_VHT_CAPABILITY_LEN),
660 	[NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
661 	[NL80211_ATTR_P2P_CTWINDOW] = NLA_POLICY_MAX(NLA_U8, 127),
662 	[NL80211_ATTR_P2P_OPPPS] = NLA_POLICY_MAX(NLA_U8, 1),
663 	[NL80211_ATTR_LOCAL_MESH_POWER_MODE] =
664 		NLA_POLICY_RANGE(NLA_U32,
665 				 NL80211_MESH_POWER_UNKNOWN + 1,
666 				 NL80211_MESH_POWER_MAX),
667 	[NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 },
668 	[NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED },
669 	[NL80211_ATTR_STA_CAPABILITY] = { .type = NLA_U16 },
670 	[NL80211_ATTR_STA_EXT_CAPABILITY] = { .type = NLA_BINARY, },
671 	[NL80211_ATTR_SPLIT_WIPHY_DUMP] = { .type = NLA_FLAG, },
672 	[NL80211_ATTR_DISABLE_VHT] = { .type = NLA_FLAG },
673 	[NL80211_ATTR_VHT_CAPABILITY_MASK] = {
674 		.len = NL80211_VHT_CAPABILITY_LEN,
675 	},
676 	[NL80211_ATTR_MDID] = { .type = NLA_U16 },
677 	[NL80211_ATTR_IE_RIC] = { .type = NLA_BINARY,
678 				  .len = IEEE80211_MAX_DATA_LEN },
679 	[NL80211_ATTR_CRIT_PROT_ID] = { .type = NLA_U16 },
680 	[NL80211_ATTR_MAX_CRIT_PROT_DURATION] =
681 		NLA_POLICY_MAX(NLA_U16, NL80211_CRIT_PROTO_MAX_DURATION),
682 	[NL80211_ATTR_PEER_AID] =
683 		NLA_POLICY_RANGE(NLA_U16, 1, IEEE80211_MAX_AID),
684 	[NL80211_ATTR_CH_SWITCH_COUNT] = { .type = NLA_U32 },
685 	[NL80211_ATTR_CH_SWITCH_BLOCK_TX] = { .type = NLA_FLAG },
686 	[NL80211_ATTR_CSA_IES] = { .type = NLA_NESTED },
687 	[NL80211_ATTR_CNTDWN_OFFS_BEACON] = { .type = NLA_BINARY },
688 	[NL80211_ATTR_CNTDWN_OFFS_PRESP] = { .type = NLA_BINARY },
689 	[NL80211_ATTR_STA_SUPPORTED_CHANNELS] = NLA_POLICY_MIN_LEN(2),
690 	/*
691 	 * The value of the Length field of the Supported Operating
692 	 * Classes element is between 2 and 253.
693 	 */
694 	[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES] =
695 		NLA_POLICY_RANGE(NLA_BINARY, 2, 253),
696 	[NL80211_ATTR_HANDLE_DFS] = { .type = NLA_FLAG },
697 	[NL80211_ATTR_OPMODE_NOTIF] = { .type = NLA_U8 },
698 	[NL80211_ATTR_VENDOR_ID] = { .type = NLA_U32 },
699 	[NL80211_ATTR_VENDOR_SUBCMD] = { .type = NLA_U32 },
700 	[NL80211_ATTR_VENDOR_DATA] = { .type = NLA_BINARY },
701 	[NL80211_ATTR_QOS_MAP] = NLA_POLICY_RANGE(NLA_BINARY,
702 						  IEEE80211_QOS_MAP_LEN_MIN,
703 						  IEEE80211_QOS_MAP_LEN_MAX),
704 	[NL80211_ATTR_MAC_HINT] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
705 	[NL80211_ATTR_WIPHY_FREQ_HINT] = { .type = NLA_U32 },
706 	[NL80211_ATTR_TDLS_PEER_CAPABILITY] = { .type = NLA_U32 },
707 	[NL80211_ATTR_SOCKET_OWNER] = { .type = NLA_FLAG },
708 	[NL80211_ATTR_CSA_C_OFFSETS_TX] = { .type = NLA_BINARY },
709 	[NL80211_ATTR_USE_RRM] = { .type = NLA_FLAG },
710 	[NL80211_ATTR_TSID] = NLA_POLICY_MAX(NLA_U8, IEEE80211_NUM_TIDS - 1),
711 	[NL80211_ATTR_USER_PRIO] =
712 		NLA_POLICY_MAX(NLA_U8, IEEE80211_NUM_UPS - 1),
713 	[NL80211_ATTR_ADMITTED_TIME] = { .type = NLA_U16 },
714 	[NL80211_ATTR_SMPS_MODE] = { .type = NLA_U8 },
715 	[NL80211_ATTR_OPER_CLASS] = { .type = NLA_U8 },
716 	[NL80211_ATTR_MAC_MASK] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
717 	[NL80211_ATTR_WIPHY_SELF_MANAGED_REG] = { .type = NLA_FLAG },
718 	[NL80211_ATTR_NETNS_FD] = { .type = NLA_U32 },
719 	[NL80211_ATTR_SCHED_SCAN_DELAY] = { .type = NLA_U32 },
720 	[NL80211_ATTR_REG_INDOOR] = { .type = NLA_FLAG },
721 	[NL80211_ATTR_PBSS] = { .type = NLA_FLAG },
722 	[NL80211_ATTR_BSS_SELECT] = { .type = NLA_NESTED },
723 	[NL80211_ATTR_STA_SUPPORT_P2P_PS] =
724 		NLA_POLICY_MAX(NLA_U8, NUM_NL80211_P2P_PS_STATUS - 1),
725 	[NL80211_ATTR_MU_MIMO_GROUP_DATA] = {
726 		.len = VHT_MUMIMO_GROUPS_DATA_LEN
727 	},
728 	[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
729 	[NL80211_ATTR_NAN_MASTER_PREF] = NLA_POLICY_MIN(NLA_U8, 1),
730 	[NL80211_ATTR_BANDS] = { .type = NLA_U32 },
731 	[NL80211_ATTR_NAN_FUNC] = { .type = NLA_NESTED },
732 	[NL80211_ATTR_FILS_KEK] = { .type = NLA_BINARY,
733 				    .len = FILS_MAX_KEK_LEN },
734 	[NL80211_ATTR_FILS_NONCES] = NLA_POLICY_EXACT_LEN_WARN(2 * FILS_NONCE_LEN),
735 	[NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED] = { .type = NLA_FLAG, },
736 	[NL80211_ATTR_BSSID] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
737 	[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI] = { .type = NLA_S8 },
738 	[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST] = {
739 		.len = sizeof(struct nl80211_bss_select_rssi_adjust)
740 	},
741 	[NL80211_ATTR_TIMEOUT_REASON] = { .type = NLA_U32 },
742 	[NL80211_ATTR_FILS_ERP_USERNAME] = { .type = NLA_BINARY,
743 					     .len = FILS_ERP_MAX_USERNAME_LEN },
744 	[NL80211_ATTR_FILS_ERP_REALM] = { .type = NLA_BINARY,
745 					  .len = FILS_ERP_MAX_REALM_LEN },
746 	[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] = { .type = NLA_U16 },
747 	[NL80211_ATTR_FILS_ERP_RRK] = { .type = NLA_BINARY,
748 					.len = FILS_ERP_MAX_RRK_LEN },
749 	[NL80211_ATTR_FILS_CACHE_ID] = NLA_POLICY_EXACT_LEN_WARN(2),
750 	[NL80211_ATTR_PMK] = { .type = NLA_BINARY, .len = PMK_MAX_LEN },
751 	[NL80211_ATTR_PMKR0_NAME] = NLA_POLICY_EXACT_LEN(WLAN_PMK_NAME_LEN),
752 	[NL80211_ATTR_SCHED_SCAN_MULTI] = { .type = NLA_FLAG },
753 	[NL80211_ATTR_EXTERNAL_AUTH_SUPPORT] = { .type = NLA_FLAG },
754 
755 	[NL80211_ATTR_TXQ_LIMIT] = { .type = NLA_U32 },
756 	[NL80211_ATTR_TXQ_MEMORY_LIMIT] = { .type = NLA_U32 },
757 	[NL80211_ATTR_TXQ_QUANTUM] = NLA_POLICY_FULL_RANGE(NLA_U32, &q_range),
758 	[NL80211_ATTR_HE_CAPABILITY] =
759 		NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_he_capa,
760 				       NL80211_HE_MAX_CAPABILITY_LEN),
761 	[NL80211_ATTR_FTM_RESPONDER] =
762 		NLA_POLICY_NESTED(nl80211_ftm_responder_policy),
763 	[NL80211_ATTR_TIMEOUT] = NLA_POLICY_MIN(NLA_U32, 1),
764 	[NL80211_ATTR_PEER_MEASUREMENTS] =
765 		NLA_POLICY_NESTED(nl80211_pmsr_attr_policy),
766 	[NL80211_ATTR_AIRTIME_WEIGHT] = NLA_POLICY_MIN(NLA_U16, 1),
767 	[NL80211_ATTR_SAE_PASSWORD] = { .type = NLA_BINARY,
768 					.len = SAE_PASSWORD_MAX_LEN },
769 	[NL80211_ATTR_TWT_RESPONDER] = { .type = NLA_FLAG },
770 	[NL80211_ATTR_HE_OBSS_PD] = NLA_POLICY_NESTED(he_obss_pd_policy),
771 	[NL80211_ATTR_VLAN_ID] = NLA_POLICY_RANGE(NLA_U16, 1, VLAN_N_VID - 2),
772 	[NL80211_ATTR_HE_BSS_COLOR] = NLA_POLICY_NESTED(he_bss_color_policy),
773 	[NL80211_ATTR_TID_CONFIG] =
774 		NLA_POLICY_NESTED_ARRAY(nl80211_tid_config_attr_policy),
775 	[NL80211_ATTR_CONTROL_PORT_NO_PREAUTH] = { .type = NLA_FLAG },
776 	[NL80211_ATTR_PMK_LIFETIME] = NLA_POLICY_MIN(NLA_U32, 1),
777 	[NL80211_ATTR_PMK_REAUTH_THRESHOLD] = NLA_POLICY_RANGE(NLA_U8, 1, 100),
778 	[NL80211_ATTR_RECEIVE_MULTICAST] = { .type = NLA_FLAG },
779 	[NL80211_ATTR_WIPHY_FREQ_OFFSET] = NLA_POLICY_RANGE(NLA_U32, 0, 999),
780 	[NL80211_ATTR_SCAN_FREQ_KHZ] = { .type = NLA_NESTED },
781 	[NL80211_ATTR_HE_6GHZ_CAPABILITY] =
782 		NLA_POLICY_EXACT_LEN(sizeof(struct ieee80211_he_6ghz_capa)),
783 	[NL80211_ATTR_FILS_DISCOVERY] =
784 		NLA_POLICY_NESTED(nl80211_fils_discovery_policy),
785 	[NL80211_ATTR_UNSOL_BCAST_PROBE_RESP] =
786 		NLA_POLICY_NESTED(nl80211_unsol_bcast_probe_resp_policy),
787 	[NL80211_ATTR_S1G_CAPABILITY] =
788 		NLA_POLICY_EXACT_LEN(IEEE80211_S1G_CAPABILITY_LEN),
789 	[NL80211_ATTR_S1G_CAPABILITY_MASK] =
790 		NLA_POLICY_EXACT_LEN(IEEE80211_S1G_CAPABILITY_LEN),
791 	[NL80211_ATTR_SAE_PWE] =
792 		NLA_POLICY_RANGE(NLA_U8, NL80211_SAE_PWE_HUNT_AND_PECK,
793 				 NL80211_SAE_PWE_BOTH),
794 	[NL80211_ATTR_RECONNECT_REQUESTED] = { .type = NLA_REJECT },
795 	[NL80211_ATTR_SAR_SPEC] = NLA_POLICY_NESTED(sar_policy),
796 	[NL80211_ATTR_DISABLE_HE] = { .type = NLA_FLAG },
797 	[NL80211_ATTR_OBSS_COLOR_BITMAP] = { .type = NLA_U64 },
798 	[NL80211_ATTR_COLOR_CHANGE_COUNT] = { .type = NLA_U8 },
799 	[NL80211_ATTR_COLOR_CHANGE_COLOR] = { .type = NLA_U8 },
800 	[NL80211_ATTR_COLOR_CHANGE_ELEMS] = NLA_POLICY_NESTED(nl80211_policy),
801 	[NL80211_ATTR_MBSSID_CONFIG] =
802 			NLA_POLICY_NESTED(nl80211_mbssid_config_policy),
803 	[NL80211_ATTR_MBSSID_ELEMS] = { .type = NLA_NESTED },
804 	[NL80211_ATTR_RADAR_BACKGROUND] = { .type = NLA_FLAG },
805 	[NL80211_ATTR_AP_SETTINGS_FLAGS] = { .type = NLA_U32 },
806 	[NL80211_ATTR_EHT_CAPABILITY] =
807 		NLA_POLICY_RANGE(NLA_BINARY,
808 				 NL80211_EHT_MIN_CAPABILITY_LEN,
809 				 NL80211_EHT_MAX_CAPABILITY_LEN),
810 	[NL80211_ATTR_DISABLE_EHT] = { .type = NLA_FLAG },
811 	[NL80211_ATTR_MLO_LINKS] =
812 		NLA_POLICY_NESTED_ARRAY(nl80211_policy),
813 	[NL80211_ATTR_MLO_LINK_ID] =
814 		NLA_POLICY_RANGE(NLA_U8, 0, IEEE80211_MLD_MAX_NUM_LINKS - 1),
815 	[NL80211_ATTR_MLD_ADDR] = NLA_POLICY_EXACT_LEN(ETH_ALEN),
816 	[NL80211_ATTR_MLO_SUPPORT] = { .type = NLA_FLAG },
817 	[NL80211_ATTR_MAX_NUM_AKM_SUITES] = { .type = NLA_REJECT },
818 	[NL80211_ATTR_PUNCT_BITMAP] =
819 		NLA_POLICY_FULL_RANGE(NLA_U32, &nl80211_punct_bitmap_range),
820 
821 	[NL80211_ATTR_MAX_HW_TIMESTAMP_PEERS] = { .type = NLA_U16 },
822 	[NL80211_ATTR_HW_TIMESTAMP_ENABLED] = { .type = NLA_FLAG },
823 	[NL80211_ATTR_EMA_RNR_ELEMS] = { .type = NLA_NESTED },
824 	[NL80211_ATTR_MLO_LINK_DISABLED] = { .type = NLA_FLAG },
825 };
826 
827 /* policy for the key attributes */
828 static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
829 	[NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
830 	[NL80211_KEY_IDX] = { .type = NLA_U8 },
831 	[NL80211_KEY_CIPHER] = { .type = NLA_U32 },
832 	[NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
833 	[NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
834 	[NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
835 	[NL80211_KEY_TYPE] = NLA_POLICY_MAX(NLA_U32, NUM_NL80211_KEYTYPES - 1),
836 	[NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
837 	[NL80211_KEY_MODE] = NLA_POLICY_RANGE(NLA_U8, 0, NL80211_KEY_SET_TX),
838 };
839 
840 /* policy for the key default flags */
841 static const struct nla_policy
842 nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
843 	[NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
844 	[NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
845 };
846 
847 #ifdef CONFIG_PM
848 /* policy for WoWLAN attributes */
849 static const struct nla_policy
850 nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
851 	[NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
852 	[NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
853 	[NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
854 	[NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
855 	[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
856 	[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
857 	[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
858 	[NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
859 	[NL80211_WOWLAN_TRIG_TCP_CONNECTION] = { .type = NLA_NESTED },
860 	[NL80211_WOWLAN_TRIG_NET_DETECT] = { .type = NLA_NESTED },
861 };
862 
863 static const struct nla_policy
864 nl80211_wowlan_tcp_policy[NUM_NL80211_WOWLAN_TCP] = {
865 	[NL80211_WOWLAN_TCP_SRC_IPV4] = { .type = NLA_U32 },
866 	[NL80211_WOWLAN_TCP_DST_IPV4] = { .type = NLA_U32 },
867 	[NL80211_WOWLAN_TCP_DST_MAC] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
868 	[NL80211_WOWLAN_TCP_SRC_PORT] = { .type = NLA_U16 },
869 	[NL80211_WOWLAN_TCP_DST_PORT] = { .type = NLA_U16 },
870 	[NL80211_WOWLAN_TCP_DATA_PAYLOAD] = NLA_POLICY_MIN_LEN(1),
871 	[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ] = {
872 		.len = sizeof(struct nl80211_wowlan_tcp_data_seq)
873 	},
874 	[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN] = {
875 		.len = sizeof(struct nl80211_wowlan_tcp_data_token)
876 	},
877 	[NL80211_WOWLAN_TCP_DATA_INTERVAL] = { .type = NLA_U32 },
878 	[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] = NLA_POLICY_MIN_LEN(1),
879 	[NL80211_WOWLAN_TCP_WAKE_MASK] = NLA_POLICY_MIN_LEN(1),
880 };
881 #endif /* CONFIG_PM */
882 
883 /* policy for coalesce rule attributes */
884 static const struct nla_policy
885 nl80211_coalesce_policy[NUM_NL80211_ATTR_COALESCE_RULE] = {
886 	[NL80211_ATTR_COALESCE_RULE_DELAY] = { .type = NLA_U32 },
887 	[NL80211_ATTR_COALESCE_RULE_CONDITION] =
888 		NLA_POLICY_RANGE(NLA_U32,
889 				 NL80211_COALESCE_CONDITION_MATCH,
890 				 NL80211_COALESCE_CONDITION_NO_MATCH),
891 	[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN] = { .type = NLA_NESTED },
892 };
893 
894 /* policy for GTK rekey offload attributes */
895 static const struct nla_policy
896 nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
897 	[NL80211_REKEY_DATA_KEK] = {
898 		.type = NLA_BINARY,
899 		.len = NL80211_KEK_EXT_LEN
900 	},
901 	[NL80211_REKEY_DATA_KCK] = {
902 		.type = NLA_BINARY,
903 		.len = NL80211_KCK_EXT_LEN_32
904 	},
905 	[NL80211_REKEY_DATA_REPLAY_CTR] = NLA_POLICY_EXACT_LEN(NL80211_REPLAY_CTR_LEN),
906 	[NL80211_REKEY_DATA_AKM] = { .type = NLA_U32 },
907 };
908 
909 static const struct nla_policy
910 nl80211_match_band_rssi_policy[NUM_NL80211_BANDS] = {
911 	[NL80211_BAND_2GHZ] = { .type = NLA_S32 },
912 	[NL80211_BAND_5GHZ] = { .type = NLA_S32 },
913 	[NL80211_BAND_6GHZ] = { .type = NLA_S32 },
914 	[NL80211_BAND_60GHZ] = { .type = NLA_S32 },
915 	[NL80211_BAND_LC]    = { .type = NLA_S32 },
916 };
917 
918 static const struct nla_policy
919 nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
920 	[NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
921 						 .len = IEEE80211_MAX_SSID_LEN },
922 	[NL80211_SCHED_SCAN_MATCH_ATTR_BSSID] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
923 	[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
924 	[NL80211_SCHED_SCAN_MATCH_PER_BAND_RSSI] =
925 		NLA_POLICY_NESTED(nl80211_match_band_rssi_policy),
926 };
927 
928 static const struct nla_policy
929 nl80211_plan_policy[NL80211_SCHED_SCAN_PLAN_MAX + 1] = {
930 	[NL80211_SCHED_SCAN_PLAN_INTERVAL] = { .type = NLA_U32 },
931 	[NL80211_SCHED_SCAN_PLAN_ITERATIONS] = { .type = NLA_U32 },
932 };
933 
934 static const struct nla_policy
935 nl80211_bss_select_policy[NL80211_BSS_SELECT_ATTR_MAX + 1] = {
936 	[NL80211_BSS_SELECT_ATTR_RSSI] = { .type = NLA_FLAG },
937 	[NL80211_BSS_SELECT_ATTR_BAND_PREF] = { .type = NLA_U32 },
938 	[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST] = {
939 		.len = sizeof(struct nl80211_bss_select_rssi_adjust)
940 	},
941 };
942 
943 /* policy for NAN function attributes */
944 static const struct nla_policy
945 nl80211_nan_func_policy[NL80211_NAN_FUNC_ATTR_MAX + 1] = {
946 	[NL80211_NAN_FUNC_TYPE] =
947 		NLA_POLICY_MAX(NLA_U8, NL80211_NAN_FUNC_MAX_TYPE),
948 	[NL80211_NAN_FUNC_SERVICE_ID] = {
949 				    .len = NL80211_NAN_FUNC_SERVICE_ID_LEN },
950 	[NL80211_NAN_FUNC_PUBLISH_TYPE] = { .type = NLA_U8 },
951 	[NL80211_NAN_FUNC_PUBLISH_BCAST] = { .type = NLA_FLAG },
952 	[NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE] = { .type = NLA_FLAG },
953 	[NL80211_NAN_FUNC_FOLLOW_UP_ID] = { .type = NLA_U8 },
954 	[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID] = { .type = NLA_U8 },
955 	[NL80211_NAN_FUNC_FOLLOW_UP_DEST] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
956 	[NL80211_NAN_FUNC_CLOSE_RANGE] = { .type = NLA_FLAG },
957 	[NL80211_NAN_FUNC_TTL] = { .type = NLA_U32 },
958 	[NL80211_NAN_FUNC_SERVICE_INFO] = { .type = NLA_BINARY,
959 			.len = NL80211_NAN_FUNC_SERVICE_SPEC_INFO_MAX_LEN },
960 	[NL80211_NAN_FUNC_SRF] = { .type = NLA_NESTED },
961 	[NL80211_NAN_FUNC_RX_MATCH_FILTER] = { .type = NLA_NESTED },
962 	[NL80211_NAN_FUNC_TX_MATCH_FILTER] = { .type = NLA_NESTED },
963 	[NL80211_NAN_FUNC_INSTANCE_ID] = { .type = NLA_U8 },
964 	[NL80211_NAN_FUNC_TERM_REASON] = { .type = NLA_U8 },
965 };
966 
967 /* policy for Service Response Filter attributes */
968 static const struct nla_policy
969 nl80211_nan_srf_policy[NL80211_NAN_SRF_ATTR_MAX + 1] = {
970 	[NL80211_NAN_SRF_INCLUDE] = { .type = NLA_FLAG },
971 	[NL80211_NAN_SRF_BF] = { .type = NLA_BINARY,
972 				 .len =  NL80211_NAN_FUNC_SRF_MAX_LEN },
973 	[NL80211_NAN_SRF_BF_IDX] = { .type = NLA_U8 },
974 	[NL80211_NAN_SRF_MAC_ADDRS] = { .type = NLA_NESTED },
975 };
976 
977 /* policy for packet pattern attributes */
978 static const struct nla_policy
979 nl80211_packet_pattern_policy[MAX_NL80211_PKTPAT + 1] = {
980 	[NL80211_PKTPAT_MASK] = { .type = NLA_BINARY, },
981 	[NL80211_PKTPAT_PATTERN] = { .type = NLA_BINARY, },
982 	[NL80211_PKTPAT_OFFSET] = { .type = NLA_U32 },
983 };
984 
nl80211_prepare_wdev_dump(struct netlink_callback * cb,struct cfg80211_registered_device ** rdev,struct wireless_dev ** wdev,struct nlattr ** attrbuf)985 static int nl80211_prepare_wdev_dump(struct netlink_callback *cb,
986 				     struct cfg80211_registered_device **rdev,
987 				     struct wireless_dev **wdev,
988 				     struct nlattr **attrbuf)
989 {
990 	int err;
991 
992 	if (!cb->args[0]) {
993 		struct nlattr **attrbuf_free = NULL;
994 
995 		if (!attrbuf) {
996 			attrbuf = kcalloc(NUM_NL80211_ATTR, sizeof(*attrbuf),
997 					  GFP_KERNEL);
998 			if (!attrbuf)
999 				return -ENOMEM;
1000 			attrbuf_free = attrbuf;
1001 		}
1002 
1003 		err = nlmsg_parse_deprecated(cb->nlh,
1004 					     GENL_HDRLEN + nl80211_fam.hdrsize,
1005 					     attrbuf, nl80211_fam.maxattr,
1006 					     nl80211_policy, NULL);
1007 		if (err) {
1008 			kfree(attrbuf_free);
1009 			return err;
1010 		}
1011 
1012 		rtnl_lock();
1013 		*wdev = __cfg80211_wdev_from_attrs(NULL, sock_net(cb->skb->sk),
1014 						   attrbuf);
1015 		kfree(attrbuf_free);
1016 		if (IS_ERR(*wdev)) {
1017 			rtnl_unlock();
1018 			return PTR_ERR(*wdev);
1019 		}
1020 		*rdev = wiphy_to_rdev((*wdev)->wiphy);
1021 		mutex_lock(&(*rdev)->wiphy.mtx);
1022 		rtnl_unlock();
1023 		/* 0 is the first index - add 1 to parse only once */
1024 		cb->args[0] = (*rdev)->wiphy_idx + 1;
1025 		cb->args[1] = (*wdev)->identifier;
1026 	} else {
1027 		/* subtract the 1 again here */
1028 		struct wiphy *wiphy;
1029 		struct wireless_dev *tmp;
1030 
1031 		rtnl_lock();
1032 		wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
1033 		if (!wiphy) {
1034 			rtnl_unlock();
1035 			return -ENODEV;
1036 		}
1037 		*rdev = wiphy_to_rdev(wiphy);
1038 		*wdev = NULL;
1039 
1040 		list_for_each_entry(tmp, &(*rdev)->wiphy.wdev_list, list) {
1041 			if (tmp->identifier == cb->args[1]) {
1042 				*wdev = tmp;
1043 				break;
1044 			}
1045 		}
1046 
1047 		if (!*wdev) {
1048 			rtnl_unlock();
1049 			return -ENODEV;
1050 		}
1051 		mutex_lock(&(*rdev)->wiphy.mtx);
1052 		rtnl_unlock();
1053 	}
1054 
1055 	return 0;
1056 }
1057 
1058 /* message building helper */
nl80211hdr_put(struct sk_buff * skb,u32 portid,u32 seq,int flags,u8 cmd)1059 void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
1060 		     int flags, u8 cmd)
1061 {
1062 	/* since there is no private header just add the generic one */
1063 	return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
1064 }
1065 
nl80211_msg_put_wmm_rules(struct sk_buff * msg,const struct ieee80211_reg_rule * rule)1066 static int nl80211_msg_put_wmm_rules(struct sk_buff *msg,
1067 				     const struct ieee80211_reg_rule *rule)
1068 {
1069 	int j;
1070 	struct nlattr *nl_wmm_rules =
1071 		nla_nest_start_noflag(msg, NL80211_FREQUENCY_ATTR_WMM);
1072 
1073 	if (!nl_wmm_rules)
1074 		goto nla_put_failure;
1075 
1076 	for (j = 0; j < IEEE80211_NUM_ACS; j++) {
1077 		struct nlattr *nl_wmm_rule = nla_nest_start_noflag(msg, j);
1078 
1079 		if (!nl_wmm_rule)
1080 			goto nla_put_failure;
1081 
1082 		if (nla_put_u16(msg, NL80211_WMMR_CW_MIN,
1083 				rule->wmm_rule.client[j].cw_min) ||
1084 		    nla_put_u16(msg, NL80211_WMMR_CW_MAX,
1085 				rule->wmm_rule.client[j].cw_max) ||
1086 		    nla_put_u8(msg, NL80211_WMMR_AIFSN,
1087 			       rule->wmm_rule.client[j].aifsn) ||
1088 		    nla_put_u16(msg, NL80211_WMMR_TXOP,
1089 			        rule->wmm_rule.client[j].cot))
1090 			goto nla_put_failure;
1091 
1092 		nla_nest_end(msg, nl_wmm_rule);
1093 	}
1094 	nla_nest_end(msg, nl_wmm_rules);
1095 
1096 	return 0;
1097 
1098 nla_put_failure:
1099 	return -ENOBUFS;
1100 }
1101 
nl80211_msg_put_channel(struct sk_buff * msg,struct wiphy * wiphy,struct ieee80211_channel * chan,bool large)1102 static int nl80211_msg_put_channel(struct sk_buff *msg, struct wiphy *wiphy,
1103 				   struct ieee80211_channel *chan,
1104 				   bool large)
1105 {
1106 	/* Some channels must be completely excluded from the
1107 	 * list to protect old user-space tools from breaking
1108 	 */
1109 	if (!large && chan->flags &
1110 	    (IEEE80211_CHAN_NO_10MHZ | IEEE80211_CHAN_NO_20MHZ))
1111 		return 0;
1112 	if (!large && chan->freq_offset)
1113 		return 0;
1114 
1115 	if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
1116 			chan->center_freq))
1117 		goto nla_put_failure;
1118 
1119 	if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_OFFSET, chan->freq_offset))
1120 		goto nla_put_failure;
1121 
1122 	if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
1123 	    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
1124 		goto nla_put_failure;
1125 	if (chan->flags & IEEE80211_CHAN_NO_IR) {
1126 		if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IR))
1127 			goto nla_put_failure;
1128 		if (nla_put_flag(msg, __NL80211_FREQUENCY_ATTR_NO_IBSS))
1129 			goto nla_put_failure;
1130 	}
1131 	if (chan->flags & IEEE80211_CHAN_RADAR) {
1132 		if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
1133 			goto nla_put_failure;
1134 		if (large) {
1135 			u32 time;
1136 
1137 			time = elapsed_jiffies_msecs(chan->dfs_state_entered);
1138 
1139 			if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_STATE,
1140 					chan->dfs_state))
1141 				goto nla_put_failure;
1142 			if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_TIME,
1143 					time))
1144 				goto nla_put_failure;
1145 			if (nla_put_u32(msg,
1146 					NL80211_FREQUENCY_ATTR_DFS_CAC_TIME,
1147 					chan->dfs_cac_ms))
1148 				goto nla_put_failure;
1149 		}
1150 	}
1151 
1152 	if (large) {
1153 		if ((chan->flags & IEEE80211_CHAN_NO_HT40MINUS) &&
1154 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_MINUS))
1155 			goto nla_put_failure;
1156 		if ((chan->flags & IEEE80211_CHAN_NO_HT40PLUS) &&
1157 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_PLUS))
1158 			goto nla_put_failure;
1159 		if ((chan->flags & IEEE80211_CHAN_NO_80MHZ) &&
1160 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_80MHZ))
1161 			goto nla_put_failure;
1162 		if ((chan->flags & IEEE80211_CHAN_NO_160MHZ) &&
1163 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_160MHZ))
1164 			goto nla_put_failure;
1165 		if ((chan->flags & IEEE80211_CHAN_INDOOR_ONLY) &&
1166 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_INDOOR_ONLY))
1167 			goto nla_put_failure;
1168 		if ((chan->flags & IEEE80211_CHAN_IR_CONCURRENT) &&
1169 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_IR_CONCURRENT))
1170 			goto nla_put_failure;
1171 		if ((chan->flags & IEEE80211_CHAN_NO_20MHZ) &&
1172 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_20MHZ))
1173 			goto nla_put_failure;
1174 		if ((chan->flags & IEEE80211_CHAN_NO_10MHZ) &&
1175 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_10MHZ))
1176 			goto nla_put_failure;
1177 		if ((chan->flags & IEEE80211_CHAN_NO_HE) &&
1178 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HE))
1179 			goto nla_put_failure;
1180 		if ((chan->flags & IEEE80211_CHAN_1MHZ) &&
1181 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_1MHZ))
1182 			goto nla_put_failure;
1183 		if ((chan->flags & IEEE80211_CHAN_2MHZ) &&
1184 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_2MHZ))
1185 			goto nla_put_failure;
1186 		if ((chan->flags & IEEE80211_CHAN_4MHZ) &&
1187 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_4MHZ))
1188 			goto nla_put_failure;
1189 		if ((chan->flags & IEEE80211_CHAN_8MHZ) &&
1190 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_8MHZ))
1191 			goto nla_put_failure;
1192 		if ((chan->flags & IEEE80211_CHAN_16MHZ) &&
1193 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_16MHZ))
1194 			goto nla_put_failure;
1195 		if ((chan->flags & IEEE80211_CHAN_NO_320MHZ) &&
1196 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_320MHZ))
1197 			goto nla_put_failure;
1198 		if ((chan->flags & IEEE80211_CHAN_NO_EHT) &&
1199 		    nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_EHT))
1200 			goto nla_put_failure;
1201 	}
1202 
1203 	if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
1204 			DBM_TO_MBM(chan->max_power)))
1205 		goto nla_put_failure;
1206 
1207 	if (large) {
1208 		const struct ieee80211_reg_rule *rule =
1209 			freq_reg_info(wiphy, MHZ_TO_KHZ(chan->center_freq));
1210 
1211 		if (!IS_ERR_OR_NULL(rule) && rule->has_wmm) {
1212 			if (nl80211_msg_put_wmm_rules(msg, rule))
1213 				goto nla_put_failure;
1214 		}
1215 	}
1216 
1217 	return 0;
1218 
1219  nla_put_failure:
1220 	return -ENOBUFS;
1221 }
1222 
nl80211_put_txq_stats(struct sk_buff * msg,struct cfg80211_txq_stats * txqstats,int attrtype)1223 static bool nl80211_put_txq_stats(struct sk_buff *msg,
1224 				  struct cfg80211_txq_stats *txqstats,
1225 				  int attrtype)
1226 {
1227 	struct nlattr *txqattr;
1228 
1229 #define PUT_TXQVAL_U32(attr, memb) do {					  \
1230 	if (txqstats->filled & BIT(NL80211_TXQ_STATS_ ## attr) &&	  \
1231 	    nla_put_u32(msg, NL80211_TXQ_STATS_ ## attr, txqstats->memb)) \
1232 		return false;						  \
1233 	} while (0)
1234 
1235 	txqattr = nla_nest_start_noflag(msg, attrtype);
1236 	if (!txqattr)
1237 		return false;
1238 
1239 	PUT_TXQVAL_U32(BACKLOG_BYTES, backlog_bytes);
1240 	PUT_TXQVAL_U32(BACKLOG_PACKETS, backlog_packets);
1241 	PUT_TXQVAL_U32(FLOWS, flows);
1242 	PUT_TXQVAL_U32(DROPS, drops);
1243 	PUT_TXQVAL_U32(ECN_MARKS, ecn_marks);
1244 	PUT_TXQVAL_U32(OVERLIMIT, overlimit);
1245 	PUT_TXQVAL_U32(OVERMEMORY, overmemory);
1246 	PUT_TXQVAL_U32(COLLISIONS, collisions);
1247 	PUT_TXQVAL_U32(TX_BYTES, tx_bytes);
1248 	PUT_TXQVAL_U32(TX_PACKETS, tx_packets);
1249 	PUT_TXQVAL_U32(MAX_FLOWS, max_flows);
1250 	nla_nest_end(msg, txqattr);
1251 
1252 #undef PUT_TXQVAL_U32
1253 	return true;
1254 }
1255 
1256 /* netlink command implementations */
1257 
1258 /**
1259  * nl80211_link_id - return link ID
1260  * @attrs: attributes to look at
1261  *
1262  * Returns: the link ID or 0 if not given
1263  *
1264  * Note this function doesn't do any validation of the link
1265  * ID validity wrt. links that were actually added, so it must
1266  * be called only from ops with %NL80211_FLAG_MLO_VALID_LINK_ID
1267  * or if additional validation is done.
1268  */
nl80211_link_id(struct nlattr ** attrs)1269 static unsigned int nl80211_link_id(struct nlattr **attrs)
1270 {
1271 	struct nlattr *linkid = attrs[NL80211_ATTR_MLO_LINK_ID];
1272 
1273 	if (!linkid)
1274 		return 0;
1275 
1276 	return nla_get_u8(linkid);
1277 }
1278 
nl80211_link_id_or_invalid(struct nlattr ** attrs)1279 static int nl80211_link_id_or_invalid(struct nlattr **attrs)
1280 {
1281 	struct nlattr *linkid = attrs[NL80211_ATTR_MLO_LINK_ID];
1282 
1283 	if (!linkid)
1284 		return -1;
1285 
1286 	return nla_get_u8(linkid);
1287 }
1288 
1289 struct key_parse {
1290 	struct key_params p;
1291 	int idx;
1292 	int type;
1293 	bool def, defmgmt, defbeacon;
1294 	bool def_uni, def_multi;
1295 };
1296 
nl80211_parse_key_new(struct genl_info * info,struct nlattr * key,struct key_parse * k)1297 static int nl80211_parse_key_new(struct genl_info *info, struct nlattr *key,
1298 				 struct key_parse *k)
1299 {
1300 	struct nlattr *tb[NL80211_KEY_MAX + 1];
1301 	int err = nla_parse_nested_deprecated(tb, NL80211_KEY_MAX, key,
1302 					      nl80211_key_policy,
1303 					      info->extack);
1304 	if (err)
1305 		return err;
1306 
1307 	k->def = !!tb[NL80211_KEY_DEFAULT];
1308 	k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
1309 	k->defbeacon = !!tb[NL80211_KEY_DEFAULT_BEACON];
1310 
1311 	if (k->def) {
1312 		k->def_uni = true;
1313 		k->def_multi = true;
1314 	}
1315 	if (k->defmgmt || k->defbeacon)
1316 		k->def_multi = true;
1317 
1318 	if (tb[NL80211_KEY_IDX])
1319 		k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
1320 
1321 	if (tb[NL80211_KEY_DATA]) {
1322 		k->p.key = nla_data(tb[NL80211_KEY_DATA]);
1323 		k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
1324 	}
1325 
1326 	if (tb[NL80211_KEY_SEQ]) {
1327 		k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
1328 		k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
1329 	}
1330 
1331 	if (tb[NL80211_KEY_CIPHER])
1332 		k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
1333 
1334 	if (tb[NL80211_KEY_TYPE])
1335 		k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
1336 
1337 	if (tb[NL80211_KEY_DEFAULT_TYPES]) {
1338 		struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
1339 
1340 		err = nla_parse_nested_deprecated(kdt,
1341 						  NUM_NL80211_KEY_DEFAULT_TYPES - 1,
1342 						  tb[NL80211_KEY_DEFAULT_TYPES],
1343 						  nl80211_key_default_policy,
1344 						  info->extack);
1345 		if (err)
1346 			return err;
1347 
1348 		k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
1349 		k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
1350 	}
1351 
1352 	if (tb[NL80211_KEY_MODE])
1353 		k->p.mode = nla_get_u8(tb[NL80211_KEY_MODE]);
1354 
1355 	return 0;
1356 }
1357 
nl80211_parse_key_old(struct genl_info * info,struct key_parse * k)1358 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
1359 {
1360 	if (info->attrs[NL80211_ATTR_KEY_DATA]) {
1361 		k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
1362 		k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
1363 	}
1364 
1365 	if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
1366 		k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
1367 		k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
1368 	}
1369 
1370 	if (info->attrs[NL80211_ATTR_KEY_IDX])
1371 		k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1372 
1373 	if (info->attrs[NL80211_ATTR_KEY_CIPHER])
1374 		k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
1375 
1376 	k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
1377 	k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
1378 
1379 	if (k->def) {
1380 		k->def_uni = true;
1381 		k->def_multi = true;
1382 	}
1383 	if (k->defmgmt)
1384 		k->def_multi = true;
1385 
1386 	if (info->attrs[NL80211_ATTR_KEY_TYPE])
1387 		k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1388 
1389 	if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
1390 		struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
1391 		int err = nla_parse_nested_deprecated(kdt,
1392 						      NUM_NL80211_KEY_DEFAULT_TYPES - 1,
1393 						      info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
1394 						      nl80211_key_default_policy,
1395 						      info->extack);
1396 		if (err)
1397 			return err;
1398 
1399 		k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
1400 		k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
1401 	}
1402 
1403 	return 0;
1404 }
1405 
nl80211_parse_key(struct genl_info * info,struct key_parse * k)1406 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
1407 {
1408 	int err;
1409 
1410 	memset(k, 0, sizeof(*k));
1411 	k->idx = -1;
1412 	k->type = -1;
1413 
1414 	if (info->attrs[NL80211_ATTR_KEY])
1415 		err = nl80211_parse_key_new(info, info->attrs[NL80211_ATTR_KEY], k);
1416 	else
1417 		err = nl80211_parse_key_old(info, k);
1418 
1419 	if (err)
1420 		return err;
1421 
1422 	if ((k->def ? 1 : 0) + (k->defmgmt ? 1 : 0) +
1423 	    (k->defbeacon ? 1 : 0) > 1) {
1424 		GENL_SET_ERR_MSG(info,
1425 				 "key with multiple default flags is invalid");
1426 		return -EINVAL;
1427 	}
1428 
1429 	if (k->defmgmt || k->defbeacon) {
1430 		if (k->def_uni || !k->def_multi) {
1431 			GENL_SET_ERR_MSG(info,
1432 					 "defmgmt/defbeacon key must be mcast");
1433 			return -EINVAL;
1434 		}
1435 	}
1436 
1437 	if (k->idx != -1) {
1438 		if (k->defmgmt) {
1439 			if (k->idx < 4 || k->idx > 5) {
1440 				GENL_SET_ERR_MSG(info,
1441 						 "defmgmt key idx not 4 or 5");
1442 				return -EINVAL;
1443 			}
1444 		} else if (k->defbeacon) {
1445 			if (k->idx < 6 || k->idx > 7) {
1446 				GENL_SET_ERR_MSG(info,
1447 						 "defbeacon key idx not 6 or 7");
1448 				return -EINVAL;
1449 			}
1450 		} else if (k->def) {
1451 			if (k->idx < 0 || k->idx > 3) {
1452 				GENL_SET_ERR_MSG(info, "def key idx not 0-3");
1453 				return -EINVAL;
1454 			}
1455 		} else {
1456 			if (k->idx < 0 || k->idx > 7) {
1457 				GENL_SET_ERR_MSG(info, "key idx not 0-7");
1458 				return -EINVAL;
1459 			}
1460 		}
1461 	}
1462 
1463 	return 0;
1464 }
1465 
1466 static struct cfg80211_cached_keys *
nl80211_parse_connkeys(struct cfg80211_registered_device * rdev,struct genl_info * info,bool * no_ht)1467 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
1468 		       struct genl_info *info, bool *no_ht)
1469 {
1470 	struct nlattr *keys = info->attrs[NL80211_ATTR_KEYS];
1471 	struct key_parse parse;
1472 	struct nlattr *key;
1473 	struct cfg80211_cached_keys *result;
1474 	int rem, err, def = 0;
1475 	bool have_key = false;
1476 
1477 	nla_for_each_nested(key, keys, rem) {
1478 		have_key = true;
1479 		break;
1480 	}
1481 
1482 	if (!have_key)
1483 		return NULL;
1484 
1485 	result = kzalloc(sizeof(*result), GFP_KERNEL);
1486 	if (!result)
1487 		return ERR_PTR(-ENOMEM);
1488 
1489 	result->def = -1;
1490 
1491 	nla_for_each_nested(key, keys, rem) {
1492 		memset(&parse, 0, sizeof(parse));
1493 		parse.idx = -1;
1494 
1495 		err = nl80211_parse_key_new(info, key, &parse);
1496 		if (err)
1497 			goto error;
1498 		err = -EINVAL;
1499 		if (!parse.p.key)
1500 			goto error;
1501 		if (parse.idx < 0 || parse.idx > 3) {
1502 			GENL_SET_ERR_MSG(info, "key index out of range [0-3]");
1503 			goto error;
1504 		}
1505 		if (parse.def) {
1506 			if (def) {
1507 				GENL_SET_ERR_MSG(info,
1508 						 "only one key can be default");
1509 				goto error;
1510 			}
1511 			def = 1;
1512 			result->def = parse.idx;
1513 			if (!parse.def_uni || !parse.def_multi)
1514 				goto error;
1515 		} else if (parse.defmgmt)
1516 			goto error;
1517 		err = cfg80211_validate_key_settings(rdev, &parse.p,
1518 						     parse.idx, false, NULL);
1519 		if (err)
1520 			goto error;
1521 		if (parse.p.cipher != WLAN_CIPHER_SUITE_WEP40 &&
1522 		    parse.p.cipher != WLAN_CIPHER_SUITE_WEP104) {
1523 			GENL_SET_ERR_MSG(info, "connect key must be WEP");
1524 			err = -EINVAL;
1525 			goto error;
1526 		}
1527 		result->params[parse.idx].cipher = parse.p.cipher;
1528 		result->params[parse.idx].key_len = parse.p.key_len;
1529 		result->params[parse.idx].key = result->data[parse.idx];
1530 		memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
1531 
1532 		/* must be WEP key if we got here */
1533 		if (no_ht)
1534 			*no_ht = true;
1535 	}
1536 
1537 	if (result->def < 0) {
1538 		err = -EINVAL;
1539 		GENL_SET_ERR_MSG(info, "need a default/TX key");
1540 		goto error;
1541 	}
1542 
1543 	return result;
1544  error:
1545 	kfree(result);
1546 	return ERR_PTR(err);
1547 }
1548 
nl80211_key_allowed(struct wireless_dev * wdev)1549 static int nl80211_key_allowed(struct wireless_dev *wdev)
1550 {
1551 	ASSERT_WDEV_LOCK(wdev);
1552 
1553 	switch (wdev->iftype) {
1554 	case NL80211_IFTYPE_AP:
1555 	case NL80211_IFTYPE_AP_VLAN:
1556 	case NL80211_IFTYPE_P2P_GO:
1557 	case NL80211_IFTYPE_MESH_POINT:
1558 		break;
1559 	case NL80211_IFTYPE_ADHOC:
1560 		if (wdev->u.ibss.current_bss)
1561 			return 0;
1562 		return -ENOLINK;
1563 	case NL80211_IFTYPE_STATION:
1564 	case NL80211_IFTYPE_P2P_CLIENT:
1565 		if (wdev->connected)
1566 			return 0;
1567 		return -ENOLINK;
1568 	case NL80211_IFTYPE_NAN:
1569 		if (wiphy_ext_feature_isset(wdev->wiphy,
1570 					    NL80211_EXT_FEATURE_SECURE_NAN))
1571 			return 0;
1572 		return -EINVAL;
1573 	case NL80211_IFTYPE_UNSPECIFIED:
1574 	case NL80211_IFTYPE_OCB:
1575 	case NL80211_IFTYPE_MONITOR:
1576 	case NL80211_IFTYPE_P2P_DEVICE:
1577 	case NL80211_IFTYPE_WDS:
1578 	case NUM_NL80211_IFTYPES:
1579 		return -EINVAL;
1580 	}
1581 
1582 	return 0;
1583 }
1584 
nl80211_get_valid_chan(struct wiphy * wiphy,u32 freq)1585 static struct ieee80211_channel *nl80211_get_valid_chan(struct wiphy *wiphy,
1586 							u32 freq)
1587 {
1588 	struct ieee80211_channel *chan;
1589 
1590 	chan = ieee80211_get_channel_khz(wiphy, freq);
1591 	if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
1592 		return NULL;
1593 	return chan;
1594 }
1595 
nl80211_put_iftypes(struct sk_buff * msg,u32 attr,u16 ifmodes)1596 static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
1597 {
1598 	struct nlattr *nl_modes = nla_nest_start_noflag(msg, attr);
1599 	int i;
1600 
1601 	if (!nl_modes)
1602 		goto nla_put_failure;
1603 
1604 	i = 0;
1605 	while (ifmodes) {
1606 		if ((ifmodes & 1) && nla_put_flag(msg, i))
1607 			goto nla_put_failure;
1608 		ifmodes >>= 1;
1609 		i++;
1610 	}
1611 
1612 	nla_nest_end(msg, nl_modes);
1613 	return 0;
1614 
1615 nla_put_failure:
1616 	return -ENOBUFS;
1617 }
1618 
nl80211_put_iface_combinations(struct wiphy * wiphy,struct sk_buff * msg,bool large)1619 static int nl80211_put_iface_combinations(struct wiphy *wiphy,
1620 					  struct sk_buff *msg,
1621 					  bool large)
1622 {
1623 	struct nlattr *nl_combis;
1624 	int i, j;
1625 
1626 	nl_combis = nla_nest_start_noflag(msg,
1627 					  NL80211_ATTR_INTERFACE_COMBINATIONS);
1628 	if (!nl_combis)
1629 		goto nla_put_failure;
1630 
1631 	for (i = 0; i < wiphy->n_iface_combinations; i++) {
1632 		const struct ieee80211_iface_combination *c;
1633 		struct nlattr *nl_combi, *nl_limits;
1634 
1635 		c = &wiphy->iface_combinations[i];
1636 
1637 		nl_combi = nla_nest_start_noflag(msg, i + 1);
1638 		if (!nl_combi)
1639 			goto nla_put_failure;
1640 
1641 		nl_limits = nla_nest_start_noflag(msg,
1642 						  NL80211_IFACE_COMB_LIMITS);
1643 		if (!nl_limits)
1644 			goto nla_put_failure;
1645 
1646 		for (j = 0; j < c->n_limits; j++) {
1647 			struct nlattr *nl_limit;
1648 
1649 			nl_limit = nla_nest_start_noflag(msg, j + 1);
1650 			if (!nl_limit)
1651 				goto nla_put_failure;
1652 			if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
1653 					c->limits[j].max))
1654 				goto nla_put_failure;
1655 			if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
1656 						c->limits[j].types))
1657 				goto nla_put_failure;
1658 			nla_nest_end(msg, nl_limit);
1659 		}
1660 
1661 		nla_nest_end(msg, nl_limits);
1662 
1663 		if (c->beacon_int_infra_match &&
1664 		    nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
1665 			goto nla_put_failure;
1666 		if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
1667 				c->num_different_channels) ||
1668 		    nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
1669 				c->max_interfaces))
1670 			goto nla_put_failure;
1671 		if (large &&
1672 		    (nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS,
1673 				c->radar_detect_widths) ||
1674 		     nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_REGIONS,
1675 				c->radar_detect_regions)))
1676 			goto nla_put_failure;
1677 		if (c->beacon_int_min_gcd &&
1678 		    nla_put_u32(msg, NL80211_IFACE_COMB_BI_MIN_GCD,
1679 				c->beacon_int_min_gcd))
1680 			goto nla_put_failure;
1681 
1682 		nla_nest_end(msg, nl_combi);
1683 	}
1684 
1685 	nla_nest_end(msg, nl_combis);
1686 
1687 	return 0;
1688 nla_put_failure:
1689 	return -ENOBUFS;
1690 }
1691 
1692 #ifdef CONFIG_PM
nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device * rdev,struct sk_buff * msg)1693 static int nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device *rdev,
1694 					struct sk_buff *msg)
1695 {
1696 	const struct wiphy_wowlan_tcp_support *tcp = rdev->wiphy.wowlan->tcp;
1697 	struct nlattr *nl_tcp;
1698 
1699 	if (!tcp)
1700 		return 0;
1701 
1702 	nl_tcp = nla_nest_start_noflag(msg,
1703 				       NL80211_WOWLAN_TRIG_TCP_CONNECTION);
1704 	if (!nl_tcp)
1705 		return -ENOBUFS;
1706 
1707 	if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
1708 			tcp->data_payload_max))
1709 		return -ENOBUFS;
1710 
1711 	if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
1712 			tcp->data_payload_max))
1713 		return -ENOBUFS;
1714 
1715 	if (tcp->seq && nla_put_flag(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ))
1716 		return -ENOBUFS;
1717 
1718 	if (tcp->tok && nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
1719 				sizeof(*tcp->tok), tcp->tok))
1720 		return -ENOBUFS;
1721 
1722 	if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
1723 			tcp->data_interval_max))
1724 		return -ENOBUFS;
1725 
1726 	if (nla_put_u32(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
1727 			tcp->wake_payload_max))
1728 		return -ENOBUFS;
1729 
1730 	nla_nest_end(msg, nl_tcp);
1731 	return 0;
1732 }
1733 
nl80211_send_wowlan(struct sk_buff * msg,struct cfg80211_registered_device * rdev,bool large)1734 static int nl80211_send_wowlan(struct sk_buff *msg,
1735 			       struct cfg80211_registered_device *rdev,
1736 			       bool large)
1737 {
1738 	struct nlattr *nl_wowlan;
1739 
1740 	if (!rdev->wiphy.wowlan)
1741 		return 0;
1742 
1743 	nl_wowlan = nla_nest_start_noflag(msg,
1744 					  NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
1745 	if (!nl_wowlan)
1746 		return -ENOBUFS;
1747 
1748 	if (((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_ANY) &&
1749 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1750 	    ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_DISCONNECT) &&
1751 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1752 	    ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT) &&
1753 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1754 	    ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
1755 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1756 	    ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
1757 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1758 	    ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
1759 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1760 	    ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
1761 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1762 	    ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
1763 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1764 		return -ENOBUFS;
1765 
1766 	if (rdev->wiphy.wowlan->n_patterns) {
1767 		struct nl80211_pattern_support pat = {
1768 			.max_patterns = rdev->wiphy.wowlan->n_patterns,
1769 			.min_pattern_len = rdev->wiphy.wowlan->pattern_min_len,
1770 			.max_pattern_len = rdev->wiphy.wowlan->pattern_max_len,
1771 			.max_pkt_offset = rdev->wiphy.wowlan->max_pkt_offset,
1772 		};
1773 
1774 		if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1775 			    sizeof(pat), &pat))
1776 			return -ENOBUFS;
1777 	}
1778 
1779 	if ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_NET_DETECT) &&
1780 	    nla_put_u32(msg, NL80211_WOWLAN_TRIG_NET_DETECT,
1781 			rdev->wiphy.wowlan->max_nd_match_sets))
1782 		return -ENOBUFS;
1783 
1784 	if (large && nl80211_send_wowlan_tcp_caps(rdev, msg))
1785 		return -ENOBUFS;
1786 
1787 	nla_nest_end(msg, nl_wowlan);
1788 
1789 	return 0;
1790 }
1791 #endif
1792 
nl80211_send_coalesce(struct sk_buff * msg,struct cfg80211_registered_device * rdev)1793 static int nl80211_send_coalesce(struct sk_buff *msg,
1794 				 struct cfg80211_registered_device *rdev)
1795 {
1796 	struct nl80211_coalesce_rule_support rule;
1797 
1798 	if (!rdev->wiphy.coalesce)
1799 		return 0;
1800 
1801 	rule.max_rules = rdev->wiphy.coalesce->n_rules;
1802 	rule.max_delay = rdev->wiphy.coalesce->max_delay;
1803 	rule.pat.max_patterns = rdev->wiphy.coalesce->n_patterns;
1804 	rule.pat.min_pattern_len = rdev->wiphy.coalesce->pattern_min_len;
1805 	rule.pat.max_pattern_len = rdev->wiphy.coalesce->pattern_max_len;
1806 	rule.pat.max_pkt_offset = rdev->wiphy.coalesce->max_pkt_offset;
1807 
1808 	if (nla_put(msg, NL80211_ATTR_COALESCE_RULE, sizeof(rule), &rule))
1809 		return -ENOBUFS;
1810 
1811 	return 0;
1812 }
1813 
1814 static int
nl80211_send_iftype_data(struct sk_buff * msg,const struct ieee80211_supported_band * sband,const struct ieee80211_sband_iftype_data * iftdata)1815 nl80211_send_iftype_data(struct sk_buff *msg,
1816 			 const struct ieee80211_supported_band *sband,
1817 			 const struct ieee80211_sband_iftype_data *iftdata)
1818 {
1819 	const struct ieee80211_sta_he_cap *he_cap = &iftdata->he_cap;
1820 	const struct ieee80211_sta_eht_cap *eht_cap = &iftdata->eht_cap;
1821 
1822 	if (nl80211_put_iftypes(msg, NL80211_BAND_IFTYPE_ATTR_IFTYPES,
1823 				iftdata->types_mask))
1824 		return -ENOBUFS;
1825 
1826 	if (he_cap->has_he) {
1827 		if (nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_CAP_MAC,
1828 			    sizeof(he_cap->he_cap_elem.mac_cap_info),
1829 			    he_cap->he_cap_elem.mac_cap_info) ||
1830 		    nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_CAP_PHY,
1831 			    sizeof(he_cap->he_cap_elem.phy_cap_info),
1832 			    he_cap->he_cap_elem.phy_cap_info) ||
1833 		    nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_CAP_MCS_SET,
1834 			    sizeof(he_cap->he_mcs_nss_supp),
1835 			    &he_cap->he_mcs_nss_supp) ||
1836 		    nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_CAP_PPE,
1837 			    sizeof(he_cap->ppe_thres), he_cap->ppe_thres))
1838 			return -ENOBUFS;
1839 	}
1840 
1841 	if (eht_cap->has_eht && he_cap->has_he) {
1842 		u8 mcs_nss_size, ppe_thresh_size;
1843 		u16 ppe_thres_hdr;
1844 		bool is_ap;
1845 
1846 		is_ap = iftdata->types_mask & BIT(NL80211_IFTYPE_AP) ||
1847 			iftdata->types_mask & BIT(NL80211_IFTYPE_P2P_GO);
1848 
1849 		mcs_nss_size =
1850 			ieee80211_eht_mcs_nss_size(&he_cap->he_cap_elem,
1851 						   &eht_cap->eht_cap_elem,
1852 						   is_ap);
1853 
1854 		ppe_thres_hdr = get_unaligned_le16(&eht_cap->eht_ppe_thres[0]);
1855 		ppe_thresh_size =
1856 			ieee80211_eht_ppe_size(ppe_thres_hdr,
1857 					       eht_cap->eht_cap_elem.phy_cap_info);
1858 
1859 		if (nla_put(msg, NL80211_BAND_IFTYPE_ATTR_EHT_CAP_MAC,
1860 			    sizeof(eht_cap->eht_cap_elem.mac_cap_info),
1861 			    eht_cap->eht_cap_elem.mac_cap_info) ||
1862 		    nla_put(msg, NL80211_BAND_IFTYPE_ATTR_EHT_CAP_PHY,
1863 			    sizeof(eht_cap->eht_cap_elem.phy_cap_info),
1864 			    eht_cap->eht_cap_elem.phy_cap_info) ||
1865 		    nla_put(msg, NL80211_BAND_IFTYPE_ATTR_EHT_CAP_MCS_SET,
1866 			    mcs_nss_size, &eht_cap->eht_mcs_nss_supp) ||
1867 		    nla_put(msg, NL80211_BAND_IFTYPE_ATTR_EHT_CAP_PPE,
1868 			    ppe_thresh_size, eht_cap->eht_ppe_thres))
1869 			return -ENOBUFS;
1870 	}
1871 
1872 	if (sband->band == NL80211_BAND_6GHZ &&
1873 	    nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_6GHZ_CAPA,
1874 		    sizeof(iftdata->he_6ghz_capa),
1875 		    &iftdata->he_6ghz_capa))
1876 		return -ENOBUFS;
1877 
1878 	if (iftdata->vendor_elems.data && iftdata->vendor_elems.len &&
1879 	    nla_put(msg, NL80211_BAND_IFTYPE_ATTR_VENDOR_ELEMS,
1880 		    iftdata->vendor_elems.len, iftdata->vendor_elems.data))
1881 		return -ENOBUFS;
1882 
1883 	return 0;
1884 }
1885 
nl80211_send_band_rateinfo(struct sk_buff * msg,struct ieee80211_supported_band * sband,bool large)1886 static int nl80211_send_band_rateinfo(struct sk_buff *msg,
1887 				      struct ieee80211_supported_band *sband,
1888 				      bool large)
1889 {
1890 	struct nlattr *nl_rates, *nl_rate;
1891 	struct ieee80211_rate *rate;
1892 	int i;
1893 
1894 	/* add HT info */
1895 	if (sband->ht_cap.ht_supported &&
1896 	    (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
1897 		     sizeof(sband->ht_cap.mcs),
1898 		     &sband->ht_cap.mcs) ||
1899 	     nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
1900 			 sband->ht_cap.cap) ||
1901 	     nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
1902 			sband->ht_cap.ampdu_factor) ||
1903 	     nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
1904 			sband->ht_cap.ampdu_density)))
1905 		return -ENOBUFS;
1906 
1907 	/* add VHT info */
1908 	if (sband->vht_cap.vht_supported &&
1909 	    (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1910 		     sizeof(sband->vht_cap.vht_mcs),
1911 		     &sband->vht_cap.vht_mcs) ||
1912 	     nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1913 			 sband->vht_cap.cap)))
1914 		return -ENOBUFS;
1915 
1916 	if (large && sband->n_iftype_data) {
1917 		struct nlattr *nl_iftype_data =
1918 			nla_nest_start_noflag(msg,
1919 					      NL80211_BAND_ATTR_IFTYPE_DATA);
1920 		int err;
1921 
1922 		if (!nl_iftype_data)
1923 			return -ENOBUFS;
1924 
1925 		for (i = 0; i < sband->n_iftype_data; i++) {
1926 			struct nlattr *iftdata;
1927 
1928 			iftdata = nla_nest_start_noflag(msg, i + 1);
1929 			if (!iftdata)
1930 				return -ENOBUFS;
1931 
1932 			err = nl80211_send_iftype_data(msg, sband,
1933 						       &sband->iftype_data[i]);
1934 			if (err)
1935 				return err;
1936 
1937 			nla_nest_end(msg, iftdata);
1938 		}
1939 
1940 		nla_nest_end(msg, nl_iftype_data);
1941 	}
1942 
1943 	/* add EDMG info */
1944 	if (large && sband->edmg_cap.channels &&
1945 	    (nla_put_u8(msg, NL80211_BAND_ATTR_EDMG_CHANNELS,
1946 		       sband->edmg_cap.channels) ||
1947 	    nla_put_u8(msg, NL80211_BAND_ATTR_EDMG_BW_CONFIG,
1948 		       sband->edmg_cap.bw_config)))
1949 
1950 		return -ENOBUFS;
1951 
1952 	/* add bitrates */
1953 	nl_rates = nla_nest_start_noflag(msg, NL80211_BAND_ATTR_RATES);
1954 	if (!nl_rates)
1955 		return -ENOBUFS;
1956 
1957 	for (i = 0; i < sband->n_bitrates; i++) {
1958 		nl_rate = nla_nest_start_noflag(msg, i);
1959 		if (!nl_rate)
1960 			return -ENOBUFS;
1961 
1962 		rate = &sband->bitrates[i];
1963 		if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1964 				rate->bitrate))
1965 			return -ENOBUFS;
1966 		if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1967 		    nla_put_flag(msg,
1968 				 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1969 			return -ENOBUFS;
1970 
1971 		nla_nest_end(msg, nl_rate);
1972 	}
1973 
1974 	nla_nest_end(msg, nl_rates);
1975 
1976 	/* S1G capabilities */
1977 	if (sband->band == NL80211_BAND_S1GHZ && sband->s1g_cap.s1g &&
1978 	    (nla_put(msg, NL80211_BAND_ATTR_S1G_CAPA,
1979 		     sizeof(sband->s1g_cap.cap),
1980 		     sband->s1g_cap.cap) ||
1981 	     nla_put(msg, NL80211_BAND_ATTR_S1G_MCS_NSS_SET,
1982 		     sizeof(sband->s1g_cap.nss_mcs),
1983 		     sband->s1g_cap.nss_mcs)))
1984 		return -ENOBUFS;
1985 
1986 	return 0;
1987 }
1988 
1989 static int
nl80211_send_mgmt_stypes(struct sk_buff * msg,const struct ieee80211_txrx_stypes * mgmt_stypes)1990 nl80211_send_mgmt_stypes(struct sk_buff *msg,
1991 			 const struct ieee80211_txrx_stypes *mgmt_stypes)
1992 {
1993 	u16 stypes;
1994 	struct nlattr *nl_ftypes, *nl_ifs;
1995 	enum nl80211_iftype ift;
1996 	int i;
1997 
1998 	if (!mgmt_stypes)
1999 		return 0;
2000 
2001 	nl_ifs = nla_nest_start_noflag(msg, NL80211_ATTR_TX_FRAME_TYPES);
2002 	if (!nl_ifs)
2003 		return -ENOBUFS;
2004 
2005 	for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
2006 		nl_ftypes = nla_nest_start_noflag(msg, ift);
2007 		if (!nl_ftypes)
2008 			return -ENOBUFS;
2009 		i = 0;
2010 		stypes = mgmt_stypes[ift].tx;
2011 		while (stypes) {
2012 			if ((stypes & 1) &&
2013 			    nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
2014 					(i << 4) | IEEE80211_FTYPE_MGMT))
2015 				return -ENOBUFS;
2016 			stypes >>= 1;
2017 			i++;
2018 		}
2019 		nla_nest_end(msg, nl_ftypes);
2020 	}
2021 
2022 	nla_nest_end(msg, nl_ifs);
2023 
2024 	nl_ifs = nla_nest_start_noflag(msg, NL80211_ATTR_RX_FRAME_TYPES);
2025 	if (!nl_ifs)
2026 		return -ENOBUFS;
2027 
2028 	for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
2029 		nl_ftypes = nla_nest_start_noflag(msg, ift);
2030 		if (!nl_ftypes)
2031 			return -ENOBUFS;
2032 		i = 0;
2033 		stypes = mgmt_stypes[ift].rx;
2034 		while (stypes) {
2035 			if ((stypes & 1) &&
2036 			    nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
2037 					(i << 4) | IEEE80211_FTYPE_MGMT))
2038 				return -ENOBUFS;
2039 			stypes >>= 1;
2040 			i++;
2041 		}
2042 		nla_nest_end(msg, nl_ftypes);
2043 	}
2044 	nla_nest_end(msg, nl_ifs);
2045 
2046 	return 0;
2047 }
2048 
2049 #define CMD(op, n)							\
2050 	 do {								\
2051 		if (rdev->ops->op) {					\
2052 			i++;						\
2053 			if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) 	\
2054 				goto nla_put_failure;			\
2055 		}							\
2056 	} while (0)
2057 
nl80211_add_commands_unsplit(struct cfg80211_registered_device * rdev,struct sk_buff * msg)2058 static int nl80211_add_commands_unsplit(struct cfg80211_registered_device *rdev,
2059 					struct sk_buff *msg)
2060 {
2061 	int i = 0;
2062 
2063 	/*
2064 	 * do *NOT* add anything into this function, new things need to be
2065 	 * advertised only to new versions of userspace that can deal with
2066 	 * the split (and they can't possibly care about new features...
2067 	 */
2068 	CMD(add_virtual_intf, NEW_INTERFACE);
2069 	CMD(change_virtual_intf, SET_INTERFACE);
2070 	CMD(add_key, NEW_KEY);
2071 	CMD(start_ap, START_AP);
2072 	CMD(add_station, NEW_STATION);
2073 	CMD(add_mpath, NEW_MPATH);
2074 	CMD(update_mesh_config, SET_MESH_CONFIG);
2075 	CMD(change_bss, SET_BSS);
2076 	CMD(auth, AUTHENTICATE);
2077 	CMD(assoc, ASSOCIATE);
2078 	CMD(deauth, DEAUTHENTICATE);
2079 	CMD(disassoc, DISASSOCIATE);
2080 	CMD(join_ibss, JOIN_IBSS);
2081 	CMD(join_mesh, JOIN_MESH);
2082 	CMD(set_pmksa, SET_PMKSA);
2083 	CMD(del_pmksa, DEL_PMKSA);
2084 	CMD(flush_pmksa, FLUSH_PMKSA);
2085 	if (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
2086 		CMD(remain_on_channel, REMAIN_ON_CHANNEL);
2087 	CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2088 	CMD(mgmt_tx, FRAME);
2089 	CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
2090 	if (rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
2091 		i++;
2092 		if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
2093 			goto nla_put_failure;
2094 	}
2095 	if (rdev->ops->set_monitor_channel || rdev->ops->start_ap ||
2096 	    rdev->ops->join_mesh) {
2097 		i++;
2098 		if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
2099 			goto nla_put_failure;
2100 	}
2101 	if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
2102 		CMD(tdls_mgmt, TDLS_MGMT);
2103 		CMD(tdls_oper, TDLS_OPER);
2104 	}
2105 	if (rdev->wiphy.max_sched_scan_reqs)
2106 		CMD(sched_scan_start, START_SCHED_SCAN);
2107 	CMD(probe_client, PROBE_CLIENT);
2108 	CMD(set_noack_map, SET_NOACK_MAP);
2109 	if (rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
2110 		i++;
2111 		if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
2112 			goto nla_put_failure;
2113 	}
2114 	CMD(start_p2p_device, START_P2P_DEVICE);
2115 	CMD(set_mcast_rate, SET_MCAST_RATE);
2116 #ifdef CONFIG_NL80211_TESTMODE
2117 	CMD(testmode_cmd, TESTMODE);
2118 #endif
2119 
2120 	if (rdev->ops->connect || rdev->ops->auth) {
2121 		i++;
2122 		if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
2123 			goto nla_put_failure;
2124 	}
2125 
2126 	if (rdev->ops->disconnect || rdev->ops->deauth) {
2127 		i++;
2128 		if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
2129 			goto nla_put_failure;
2130 	}
2131 
2132 	return i;
2133  nla_put_failure:
2134 	return -ENOBUFS;
2135 }
2136 
2137 static int
nl80211_send_pmsr_ftm_capa(const struct cfg80211_pmsr_capabilities * cap,struct sk_buff * msg)2138 nl80211_send_pmsr_ftm_capa(const struct cfg80211_pmsr_capabilities *cap,
2139 			   struct sk_buff *msg)
2140 {
2141 	struct nlattr *ftm;
2142 
2143 	if (!cap->ftm.supported)
2144 		return 0;
2145 
2146 	ftm = nla_nest_start_noflag(msg, NL80211_PMSR_TYPE_FTM);
2147 	if (!ftm)
2148 		return -ENOBUFS;
2149 
2150 	if (cap->ftm.asap && nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_ASAP))
2151 		return -ENOBUFS;
2152 	if (cap->ftm.non_asap &&
2153 	    nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_NON_ASAP))
2154 		return -ENOBUFS;
2155 	if (cap->ftm.request_lci &&
2156 	    nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_REQ_LCI))
2157 		return -ENOBUFS;
2158 	if (cap->ftm.request_civicloc &&
2159 	    nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_REQ_CIVICLOC))
2160 		return -ENOBUFS;
2161 	if (nla_put_u32(msg, NL80211_PMSR_FTM_CAPA_ATTR_PREAMBLES,
2162 			cap->ftm.preambles))
2163 		return -ENOBUFS;
2164 	if (nla_put_u32(msg, NL80211_PMSR_FTM_CAPA_ATTR_BANDWIDTHS,
2165 			cap->ftm.bandwidths))
2166 		return -ENOBUFS;
2167 	if (cap->ftm.max_bursts_exponent >= 0 &&
2168 	    nla_put_u32(msg, NL80211_PMSR_FTM_CAPA_ATTR_MAX_BURSTS_EXPONENT,
2169 			cap->ftm.max_bursts_exponent))
2170 		return -ENOBUFS;
2171 	if (cap->ftm.max_ftms_per_burst &&
2172 	    nla_put_u32(msg, NL80211_PMSR_FTM_CAPA_ATTR_MAX_FTMS_PER_BURST,
2173 			cap->ftm.max_ftms_per_burst))
2174 		return -ENOBUFS;
2175 	if (cap->ftm.trigger_based &&
2176 	    nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_TRIGGER_BASED))
2177 		return -ENOBUFS;
2178 	if (cap->ftm.non_trigger_based &&
2179 	    nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_NON_TRIGGER_BASED))
2180 		return -ENOBUFS;
2181 
2182 	nla_nest_end(msg, ftm);
2183 	return 0;
2184 }
2185 
nl80211_send_pmsr_capa(struct cfg80211_registered_device * rdev,struct sk_buff * msg)2186 static int nl80211_send_pmsr_capa(struct cfg80211_registered_device *rdev,
2187 				  struct sk_buff *msg)
2188 {
2189 	const struct cfg80211_pmsr_capabilities *cap = rdev->wiphy.pmsr_capa;
2190 	struct nlattr *pmsr, *caps;
2191 
2192 	if (!cap)
2193 		return 0;
2194 
2195 	/*
2196 	 * we don't need to clean up anything here since the caller
2197 	 * will genlmsg_cancel() if we fail
2198 	 */
2199 
2200 	pmsr = nla_nest_start_noflag(msg, NL80211_ATTR_PEER_MEASUREMENTS);
2201 	if (!pmsr)
2202 		return -ENOBUFS;
2203 
2204 	if (nla_put_u32(msg, NL80211_PMSR_ATTR_MAX_PEERS, cap->max_peers))
2205 		return -ENOBUFS;
2206 
2207 	if (cap->report_ap_tsf &&
2208 	    nla_put_flag(msg, NL80211_PMSR_ATTR_REPORT_AP_TSF))
2209 		return -ENOBUFS;
2210 
2211 	if (cap->randomize_mac_addr &&
2212 	    nla_put_flag(msg, NL80211_PMSR_ATTR_RANDOMIZE_MAC_ADDR))
2213 		return -ENOBUFS;
2214 
2215 	caps = nla_nest_start_noflag(msg, NL80211_PMSR_ATTR_TYPE_CAPA);
2216 	if (!caps)
2217 		return -ENOBUFS;
2218 
2219 	if (nl80211_send_pmsr_ftm_capa(cap, msg))
2220 		return -ENOBUFS;
2221 
2222 	nla_nest_end(msg, caps);
2223 	nla_nest_end(msg, pmsr);
2224 
2225 	return 0;
2226 }
2227 
2228 static int
nl80211_put_iftype_akm_suites(struct cfg80211_registered_device * rdev,struct sk_buff * msg)2229 nl80211_put_iftype_akm_suites(struct cfg80211_registered_device *rdev,
2230 			      struct sk_buff *msg)
2231 {
2232 	int i;
2233 	struct nlattr *nested, *nested_akms;
2234 	const struct wiphy_iftype_akm_suites *iftype_akms;
2235 
2236 	if (!rdev->wiphy.num_iftype_akm_suites ||
2237 	    !rdev->wiphy.iftype_akm_suites)
2238 		return 0;
2239 
2240 	nested = nla_nest_start(msg, NL80211_ATTR_IFTYPE_AKM_SUITES);
2241 	if (!nested)
2242 		return -ENOBUFS;
2243 
2244 	for (i = 0; i < rdev->wiphy.num_iftype_akm_suites; i++) {
2245 		nested_akms = nla_nest_start(msg, i + 1);
2246 		if (!nested_akms)
2247 			return -ENOBUFS;
2248 
2249 		iftype_akms = &rdev->wiphy.iftype_akm_suites[i];
2250 
2251 		if (nl80211_put_iftypes(msg, NL80211_IFTYPE_AKM_ATTR_IFTYPES,
2252 					iftype_akms->iftypes_mask))
2253 			return -ENOBUFS;
2254 
2255 		if (nla_put(msg, NL80211_IFTYPE_AKM_ATTR_SUITES,
2256 			    sizeof(u32) * iftype_akms->n_akm_suites,
2257 			    iftype_akms->akm_suites)) {
2258 			return -ENOBUFS;
2259 		}
2260 		nla_nest_end(msg, nested_akms);
2261 	}
2262 
2263 	nla_nest_end(msg, nested);
2264 
2265 	return 0;
2266 }
2267 
2268 static int
nl80211_put_tid_config_support(struct cfg80211_registered_device * rdev,struct sk_buff * msg)2269 nl80211_put_tid_config_support(struct cfg80211_registered_device *rdev,
2270 			       struct sk_buff *msg)
2271 {
2272 	struct nlattr *supp;
2273 
2274 	if (!rdev->wiphy.tid_config_support.vif &&
2275 	    !rdev->wiphy.tid_config_support.peer)
2276 		return 0;
2277 
2278 	supp = nla_nest_start(msg, NL80211_ATTR_TID_CONFIG);
2279 	if (!supp)
2280 		return -ENOSPC;
2281 
2282 	if (rdev->wiphy.tid_config_support.vif &&
2283 	    nla_put_u64_64bit(msg, NL80211_TID_CONFIG_ATTR_VIF_SUPP,
2284 			      rdev->wiphy.tid_config_support.vif,
2285 			      NL80211_TID_CONFIG_ATTR_PAD))
2286 		goto fail;
2287 
2288 	if (rdev->wiphy.tid_config_support.peer &&
2289 	    nla_put_u64_64bit(msg, NL80211_TID_CONFIG_ATTR_PEER_SUPP,
2290 			      rdev->wiphy.tid_config_support.peer,
2291 			      NL80211_TID_CONFIG_ATTR_PAD))
2292 		goto fail;
2293 
2294 	/* for now we just use the same value ... makes more sense */
2295 	if (nla_put_u8(msg, NL80211_TID_CONFIG_ATTR_RETRY_SHORT,
2296 		       rdev->wiphy.tid_config_support.max_retry))
2297 		goto fail;
2298 	if (nla_put_u8(msg, NL80211_TID_CONFIG_ATTR_RETRY_LONG,
2299 		       rdev->wiphy.tid_config_support.max_retry))
2300 		goto fail;
2301 
2302 	nla_nest_end(msg, supp);
2303 
2304 	return 0;
2305 fail:
2306 	nla_nest_cancel(msg, supp);
2307 	return -ENOBUFS;
2308 }
2309 
2310 static int
nl80211_put_sar_specs(struct cfg80211_registered_device * rdev,struct sk_buff * msg)2311 nl80211_put_sar_specs(struct cfg80211_registered_device *rdev,
2312 		      struct sk_buff *msg)
2313 {
2314 	struct nlattr *sar_capa, *specs, *sub_freq_range;
2315 	u8 num_freq_ranges;
2316 	int i;
2317 
2318 	if (!rdev->wiphy.sar_capa)
2319 		return 0;
2320 
2321 	num_freq_ranges = rdev->wiphy.sar_capa->num_freq_ranges;
2322 
2323 	sar_capa = nla_nest_start(msg, NL80211_ATTR_SAR_SPEC);
2324 	if (!sar_capa)
2325 		return -ENOSPC;
2326 
2327 	if (nla_put_u32(msg, NL80211_SAR_ATTR_TYPE, rdev->wiphy.sar_capa->type))
2328 		goto fail;
2329 
2330 	specs = nla_nest_start(msg, NL80211_SAR_ATTR_SPECS);
2331 	if (!specs)
2332 		goto fail;
2333 
2334 	/* report supported freq_ranges */
2335 	for (i = 0; i < num_freq_ranges; i++) {
2336 		sub_freq_range = nla_nest_start(msg, i + 1);
2337 		if (!sub_freq_range)
2338 			goto fail;
2339 
2340 		if (nla_put_u32(msg, NL80211_SAR_ATTR_SPECS_START_FREQ,
2341 				rdev->wiphy.sar_capa->freq_ranges[i].start_freq))
2342 			goto fail;
2343 
2344 		if (nla_put_u32(msg, NL80211_SAR_ATTR_SPECS_END_FREQ,
2345 				rdev->wiphy.sar_capa->freq_ranges[i].end_freq))
2346 			goto fail;
2347 
2348 		nla_nest_end(msg, sub_freq_range);
2349 	}
2350 
2351 	nla_nest_end(msg, specs);
2352 	nla_nest_end(msg, sar_capa);
2353 
2354 	return 0;
2355 fail:
2356 	nla_nest_cancel(msg, sar_capa);
2357 	return -ENOBUFS;
2358 }
2359 
nl80211_put_mbssid_support(struct wiphy * wiphy,struct sk_buff * msg)2360 static int nl80211_put_mbssid_support(struct wiphy *wiphy, struct sk_buff *msg)
2361 {
2362 	struct nlattr *config;
2363 
2364 	if (!wiphy->mbssid_max_interfaces)
2365 		return 0;
2366 
2367 	config = nla_nest_start(msg, NL80211_ATTR_MBSSID_CONFIG);
2368 	if (!config)
2369 		return -ENOBUFS;
2370 
2371 	if (nla_put_u8(msg, NL80211_MBSSID_CONFIG_ATTR_MAX_INTERFACES,
2372 		       wiphy->mbssid_max_interfaces))
2373 		goto fail;
2374 
2375 	if (wiphy->ema_max_profile_periodicity &&
2376 	    nla_put_u8(msg,
2377 		       NL80211_MBSSID_CONFIG_ATTR_MAX_EMA_PROFILE_PERIODICITY,
2378 		       wiphy->ema_max_profile_periodicity))
2379 		goto fail;
2380 
2381 	nla_nest_end(msg, config);
2382 	return 0;
2383 
2384 fail:
2385 	nla_nest_cancel(msg, config);
2386 	return -ENOBUFS;
2387 }
2388 
2389 struct nl80211_dump_wiphy_state {
2390 	s64 filter_wiphy;
2391 	long start;
2392 	long split_start, band_start, chan_start, capa_start;
2393 	bool split;
2394 };
2395 
nl80211_send_wiphy(struct cfg80211_registered_device * rdev,enum nl80211_commands cmd,struct sk_buff * msg,u32 portid,u32 seq,int flags,struct nl80211_dump_wiphy_state * state)2396 static int nl80211_send_wiphy(struct cfg80211_registered_device *rdev,
2397 			      enum nl80211_commands cmd,
2398 			      struct sk_buff *msg, u32 portid, u32 seq,
2399 			      int flags, struct nl80211_dump_wiphy_state *state)
2400 {
2401 	void *hdr;
2402 	struct nlattr *nl_bands, *nl_band;
2403 	struct nlattr *nl_freqs, *nl_freq;
2404 	struct nlattr *nl_cmds;
2405 	enum nl80211_band band;
2406 	struct ieee80211_channel *chan;
2407 	int i;
2408 	const struct ieee80211_txrx_stypes *mgmt_stypes =
2409 				rdev->wiphy.mgmt_stypes;
2410 	u32 features;
2411 
2412 	hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2413 	if (!hdr)
2414 		return -ENOBUFS;
2415 
2416 	if (WARN_ON(!state))
2417 		return -EINVAL;
2418 
2419 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2420 	    nla_put_string(msg, NL80211_ATTR_WIPHY_NAME,
2421 			   wiphy_name(&rdev->wiphy)) ||
2422 	    nla_put_u32(msg, NL80211_ATTR_GENERATION,
2423 			cfg80211_rdev_list_generation))
2424 		goto nla_put_failure;
2425 
2426 	if (cmd != NL80211_CMD_NEW_WIPHY)
2427 		goto finish;
2428 
2429 	switch (state->split_start) {
2430 	case 0:
2431 		if (nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
2432 			       rdev->wiphy.retry_short) ||
2433 		    nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
2434 			       rdev->wiphy.retry_long) ||
2435 		    nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
2436 				rdev->wiphy.frag_threshold) ||
2437 		    nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
2438 				rdev->wiphy.rts_threshold) ||
2439 		    nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
2440 			       rdev->wiphy.coverage_class) ||
2441 		    nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
2442 			       rdev->wiphy.max_scan_ssids) ||
2443 		    nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
2444 			       rdev->wiphy.max_sched_scan_ssids) ||
2445 		    nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
2446 				rdev->wiphy.max_scan_ie_len) ||
2447 		    nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
2448 				rdev->wiphy.max_sched_scan_ie_len) ||
2449 		    nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
2450 			       rdev->wiphy.max_match_sets))
2451 			goto nla_put_failure;
2452 
2453 		if ((rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
2454 		    nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
2455 			goto nla_put_failure;
2456 		if ((rdev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
2457 		    nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
2458 			goto nla_put_failure;
2459 		if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
2460 		    nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
2461 			goto nla_put_failure;
2462 		if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
2463 		    nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
2464 			goto nla_put_failure;
2465 		if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
2466 		    nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
2467 			goto nla_put_failure;
2468 		if ((rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
2469 		    nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
2470 			goto nla_put_failure;
2471 		state->split_start++;
2472 		if (state->split)
2473 			break;
2474 		fallthrough;
2475 	case 1:
2476 		if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
2477 			    sizeof(u32) * rdev->wiphy.n_cipher_suites,
2478 			    rdev->wiphy.cipher_suites))
2479 			goto nla_put_failure;
2480 
2481 		if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
2482 			       rdev->wiphy.max_num_pmkids))
2483 			goto nla_put_failure;
2484 
2485 		if ((rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
2486 		    nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
2487 			goto nla_put_failure;
2488 
2489 		if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
2490 				rdev->wiphy.available_antennas_tx) ||
2491 		    nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
2492 				rdev->wiphy.available_antennas_rx))
2493 			goto nla_put_failure;
2494 
2495 		if ((rdev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
2496 		    nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
2497 				rdev->wiphy.probe_resp_offload))
2498 			goto nla_put_failure;
2499 
2500 		if ((rdev->wiphy.available_antennas_tx ||
2501 		     rdev->wiphy.available_antennas_rx) &&
2502 		    rdev->ops->get_antenna) {
2503 			u32 tx_ant = 0, rx_ant = 0;
2504 			int res;
2505 
2506 			res = rdev_get_antenna(rdev, &tx_ant, &rx_ant);
2507 			if (!res) {
2508 				if (nla_put_u32(msg,
2509 						NL80211_ATTR_WIPHY_ANTENNA_TX,
2510 						tx_ant) ||
2511 				    nla_put_u32(msg,
2512 						NL80211_ATTR_WIPHY_ANTENNA_RX,
2513 						rx_ant))
2514 					goto nla_put_failure;
2515 			}
2516 		}
2517 
2518 		state->split_start++;
2519 		if (state->split)
2520 			break;
2521 		fallthrough;
2522 	case 2:
2523 		if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
2524 					rdev->wiphy.interface_modes))
2525 				goto nla_put_failure;
2526 		state->split_start++;
2527 		if (state->split)
2528 			break;
2529 		fallthrough;
2530 	case 3:
2531 		nl_bands = nla_nest_start_noflag(msg,
2532 						 NL80211_ATTR_WIPHY_BANDS);
2533 		if (!nl_bands)
2534 			goto nla_put_failure;
2535 
2536 		for (band = state->band_start;
2537 		     band < (state->split ?
2538 				NUM_NL80211_BANDS :
2539 				NL80211_BAND_60GHZ + 1);
2540 		     band++) {
2541 			struct ieee80211_supported_band *sband;
2542 
2543 			/* omit higher bands for ancient software */
2544 			if (band > NL80211_BAND_5GHZ && !state->split)
2545 				break;
2546 
2547 			sband = rdev->wiphy.bands[band];
2548 
2549 			if (!sband)
2550 				continue;
2551 
2552 			nl_band = nla_nest_start_noflag(msg, band);
2553 			if (!nl_band)
2554 				goto nla_put_failure;
2555 
2556 			switch (state->chan_start) {
2557 			case 0:
2558 				if (nl80211_send_band_rateinfo(msg, sband,
2559 							       state->split))
2560 					goto nla_put_failure;
2561 				state->chan_start++;
2562 				if (state->split)
2563 					break;
2564 				fallthrough;
2565 			default:
2566 				/* add frequencies */
2567 				nl_freqs = nla_nest_start_noflag(msg,
2568 								 NL80211_BAND_ATTR_FREQS);
2569 				if (!nl_freqs)
2570 					goto nla_put_failure;
2571 
2572 				for (i = state->chan_start - 1;
2573 				     i < sband->n_channels;
2574 				     i++) {
2575 					nl_freq = nla_nest_start_noflag(msg,
2576 									i);
2577 					if (!nl_freq)
2578 						goto nla_put_failure;
2579 
2580 					chan = &sband->channels[i];
2581 
2582 					if (nl80211_msg_put_channel(
2583 							msg, &rdev->wiphy, chan,
2584 							state->split))
2585 						goto nla_put_failure;
2586 
2587 					nla_nest_end(msg, nl_freq);
2588 					if (state->split)
2589 						break;
2590 				}
2591 				if (i < sband->n_channels)
2592 					state->chan_start = i + 2;
2593 				else
2594 					state->chan_start = 0;
2595 				nla_nest_end(msg, nl_freqs);
2596 			}
2597 
2598 			nla_nest_end(msg, nl_band);
2599 
2600 			if (state->split) {
2601 				/* start again here */
2602 				if (state->chan_start)
2603 					band--;
2604 				break;
2605 			}
2606 		}
2607 		nla_nest_end(msg, nl_bands);
2608 
2609 		if (band < NUM_NL80211_BANDS)
2610 			state->band_start = band + 1;
2611 		else
2612 			state->band_start = 0;
2613 
2614 		/* if bands & channels are done, continue outside */
2615 		if (state->band_start == 0 && state->chan_start == 0)
2616 			state->split_start++;
2617 		if (state->split)
2618 			break;
2619 		fallthrough;
2620 	case 4:
2621 		nl_cmds = nla_nest_start_noflag(msg,
2622 						NL80211_ATTR_SUPPORTED_COMMANDS);
2623 		if (!nl_cmds)
2624 			goto nla_put_failure;
2625 
2626 		i = nl80211_add_commands_unsplit(rdev, msg);
2627 		if (i < 0)
2628 			goto nla_put_failure;
2629 		if (state->split) {
2630 			CMD(crit_proto_start, CRIT_PROTOCOL_START);
2631 			CMD(crit_proto_stop, CRIT_PROTOCOL_STOP);
2632 			if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH)
2633 				CMD(channel_switch, CHANNEL_SWITCH);
2634 			CMD(set_qos_map, SET_QOS_MAP);
2635 			if (rdev->wiphy.features &
2636 					NL80211_FEATURE_SUPPORTS_WMM_ADMISSION)
2637 				CMD(add_tx_ts, ADD_TX_TS);
2638 			CMD(set_multicast_to_unicast, SET_MULTICAST_TO_UNICAST);
2639 			CMD(update_connect_params, UPDATE_CONNECT_PARAMS);
2640 			CMD(update_ft_ies, UPDATE_FT_IES);
2641 			if (rdev->wiphy.sar_capa)
2642 				CMD(set_sar_specs, SET_SAR_SPECS);
2643 		}
2644 #undef CMD
2645 
2646 		nla_nest_end(msg, nl_cmds);
2647 		state->split_start++;
2648 		if (state->split)
2649 			break;
2650 		fallthrough;
2651 	case 5:
2652 		if (rdev->ops->remain_on_channel &&
2653 		    (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
2654 		    nla_put_u32(msg,
2655 				NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
2656 				rdev->wiphy.max_remain_on_channel_duration))
2657 			goto nla_put_failure;
2658 
2659 		if ((rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
2660 		    nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
2661 			goto nla_put_failure;
2662 
2663 		state->split_start++;
2664 		if (state->split)
2665 			break;
2666 		fallthrough;
2667 	case 6:
2668 #ifdef CONFIG_PM
2669 		if (nl80211_send_wowlan(msg, rdev, state->split))
2670 			goto nla_put_failure;
2671 		state->split_start++;
2672 		if (state->split)
2673 			break;
2674 #else
2675 		state->split_start++;
2676 #endif
2677 		fallthrough;
2678 	case 7:
2679 		if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
2680 					rdev->wiphy.software_iftypes))
2681 			goto nla_put_failure;
2682 
2683 		if (nl80211_put_iface_combinations(&rdev->wiphy, msg,
2684 						   state->split))
2685 			goto nla_put_failure;
2686 
2687 		state->split_start++;
2688 		if (state->split)
2689 			break;
2690 		fallthrough;
2691 	case 8:
2692 		if ((rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
2693 		    nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
2694 				rdev->wiphy.ap_sme_capa))
2695 			goto nla_put_failure;
2696 
2697 		features = rdev->wiphy.features;
2698 		/*
2699 		 * We can only add the per-channel limit information if the
2700 		 * dump is split, otherwise it makes it too big. Therefore
2701 		 * only advertise it in that case.
2702 		 */
2703 		if (state->split)
2704 			features |= NL80211_FEATURE_ADVERTISE_CHAN_LIMITS;
2705 		if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS, features))
2706 			goto nla_put_failure;
2707 
2708 		if (rdev->wiphy.ht_capa_mod_mask &&
2709 		    nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
2710 			    sizeof(*rdev->wiphy.ht_capa_mod_mask),
2711 			    rdev->wiphy.ht_capa_mod_mask))
2712 			goto nla_put_failure;
2713 
2714 		if (rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME &&
2715 		    rdev->wiphy.max_acl_mac_addrs &&
2716 		    nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX,
2717 				rdev->wiphy.max_acl_mac_addrs))
2718 			goto nla_put_failure;
2719 
2720 		/*
2721 		 * Any information below this point is only available to
2722 		 * applications that can deal with it being split. This
2723 		 * helps ensure that newly added capabilities don't break
2724 		 * older tools by overrunning their buffers.
2725 		 *
2726 		 * We still increment split_start so that in the split
2727 		 * case we'll continue with more data in the next round,
2728 		 * but break unconditionally so unsplit data stops here.
2729 		 */
2730 		if (state->split)
2731 			state->split_start++;
2732 		else
2733 			state->split_start = 0;
2734 		break;
2735 	case 9:
2736 		if (nl80211_send_mgmt_stypes(msg, mgmt_stypes))
2737 			goto nla_put_failure;
2738 
2739 		if (nla_put_u32(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_PLANS,
2740 				rdev->wiphy.max_sched_scan_plans) ||
2741 		    nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_INTERVAL,
2742 				rdev->wiphy.max_sched_scan_plan_interval) ||
2743 		    nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_ITERATIONS,
2744 				rdev->wiphy.max_sched_scan_plan_iterations))
2745 			goto nla_put_failure;
2746 
2747 		if (rdev->wiphy.extended_capabilities &&
2748 		    (nla_put(msg, NL80211_ATTR_EXT_CAPA,
2749 			     rdev->wiphy.extended_capabilities_len,
2750 			     rdev->wiphy.extended_capabilities) ||
2751 		     nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
2752 			     rdev->wiphy.extended_capabilities_len,
2753 			     rdev->wiphy.extended_capabilities_mask)))
2754 			goto nla_put_failure;
2755 
2756 		if (rdev->wiphy.vht_capa_mod_mask &&
2757 		    nla_put(msg, NL80211_ATTR_VHT_CAPABILITY_MASK,
2758 			    sizeof(*rdev->wiphy.vht_capa_mod_mask),
2759 			    rdev->wiphy.vht_capa_mod_mask))
2760 			goto nla_put_failure;
2761 
2762 		if (nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN,
2763 			    rdev->wiphy.perm_addr))
2764 			goto nla_put_failure;
2765 
2766 		if (!is_zero_ether_addr(rdev->wiphy.addr_mask) &&
2767 		    nla_put(msg, NL80211_ATTR_MAC_MASK, ETH_ALEN,
2768 			    rdev->wiphy.addr_mask))
2769 			goto nla_put_failure;
2770 
2771 		if (rdev->wiphy.n_addresses > 1) {
2772 			void *attr;
2773 
2774 			attr = nla_nest_start(msg, NL80211_ATTR_MAC_ADDRS);
2775 			if (!attr)
2776 				goto nla_put_failure;
2777 
2778 			for (i = 0; i < rdev->wiphy.n_addresses; i++)
2779 				if (nla_put(msg, i + 1, ETH_ALEN,
2780 					    rdev->wiphy.addresses[i].addr))
2781 					goto nla_put_failure;
2782 
2783 			nla_nest_end(msg, attr);
2784 		}
2785 
2786 		state->split_start++;
2787 		break;
2788 	case 10:
2789 		if (nl80211_send_coalesce(msg, rdev))
2790 			goto nla_put_failure;
2791 
2792 		if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ) &&
2793 		    (nla_put_flag(msg, NL80211_ATTR_SUPPORT_5_MHZ) ||
2794 		     nla_put_flag(msg, NL80211_ATTR_SUPPORT_10_MHZ)))
2795 			goto nla_put_failure;
2796 
2797 		if (rdev->wiphy.max_ap_assoc_sta &&
2798 		    nla_put_u32(msg, NL80211_ATTR_MAX_AP_ASSOC_STA,
2799 				rdev->wiphy.max_ap_assoc_sta))
2800 			goto nla_put_failure;
2801 
2802 		state->split_start++;
2803 		break;
2804 	case 11:
2805 		if (rdev->wiphy.n_vendor_commands) {
2806 			const struct nl80211_vendor_cmd_info *info;
2807 			struct nlattr *nested;
2808 
2809 			nested = nla_nest_start_noflag(msg,
2810 						       NL80211_ATTR_VENDOR_DATA);
2811 			if (!nested)
2812 				goto nla_put_failure;
2813 
2814 			for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) {
2815 				info = &rdev->wiphy.vendor_commands[i].info;
2816 				if (nla_put(msg, i + 1, sizeof(*info), info))
2817 					goto nla_put_failure;
2818 			}
2819 			nla_nest_end(msg, nested);
2820 		}
2821 
2822 		if (rdev->wiphy.n_vendor_events) {
2823 			const struct nl80211_vendor_cmd_info *info;
2824 			struct nlattr *nested;
2825 
2826 			nested = nla_nest_start_noflag(msg,
2827 						       NL80211_ATTR_VENDOR_EVENTS);
2828 			if (!nested)
2829 				goto nla_put_failure;
2830 
2831 			for (i = 0; i < rdev->wiphy.n_vendor_events; i++) {
2832 				info = &rdev->wiphy.vendor_events[i];
2833 				if (nla_put(msg, i + 1, sizeof(*info), info))
2834 					goto nla_put_failure;
2835 			}
2836 			nla_nest_end(msg, nested);
2837 		}
2838 		state->split_start++;
2839 		break;
2840 	case 12:
2841 		if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH &&
2842 		    nla_put_u8(msg, NL80211_ATTR_MAX_CSA_COUNTERS,
2843 			       rdev->wiphy.max_num_csa_counters))
2844 			goto nla_put_failure;
2845 
2846 		if (rdev->wiphy.regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
2847 		    nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
2848 			goto nla_put_failure;
2849 
2850 		if (rdev->wiphy.max_sched_scan_reqs &&
2851 		    nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_MAX_REQS,
2852 				rdev->wiphy.max_sched_scan_reqs))
2853 			goto nla_put_failure;
2854 
2855 		if (nla_put(msg, NL80211_ATTR_EXT_FEATURES,
2856 			    sizeof(rdev->wiphy.ext_features),
2857 			    rdev->wiphy.ext_features))
2858 			goto nla_put_failure;
2859 
2860 		if (rdev->wiphy.bss_select_support) {
2861 			struct nlattr *nested;
2862 			u32 bss_select_support = rdev->wiphy.bss_select_support;
2863 
2864 			nested = nla_nest_start_noflag(msg,
2865 						       NL80211_ATTR_BSS_SELECT);
2866 			if (!nested)
2867 				goto nla_put_failure;
2868 
2869 			i = 0;
2870 			while (bss_select_support) {
2871 				if ((bss_select_support & 1) &&
2872 				    nla_put_flag(msg, i))
2873 					goto nla_put_failure;
2874 				i++;
2875 				bss_select_support >>= 1;
2876 			}
2877 			nla_nest_end(msg, nested);
2878 		}
2879 
2880 		state->split_start++;
2881 		break;
2882 	case 13:
2883 		if (rdev->wiphy.num_iftype_ext_capab &&
2884 		    rdev->wiphy.iftype_ext_capab) {
2885 			struct nlattr *nested_ext_capab, *nested;
2886 
2887 			nested = nla_nest_start_noflag(msg,
2888 						       NL80211_ATTR_IFTYPE_EXT_CAPA);
2889 			if (!nested)
2890 				goto nla_put_failure;
2891 
2892 			for (i = state->capa_start;
2893 			     i < rdev->wiphy.num_iftype_ext_capab; i++) {
2894 				const struct wiphy_iftype_ext_capab *capab;
2895 
2896 				capab = &rdev->wiphy.iftype_ext_capab[i];
2897 
2898 				nested_ext_capab = nla_nest_start_noflag(msg,
2899 									 i);
2900 				if (!nested_ext_capab ||
2901 				    nla_put_u32(msg, NL80211_ATTR_IFTYPE,
2902 						capab->iftype) ||
2903 				    nla_put(msg, NL80211_ATTR_EXT_CAPA,
2904 					    capab->extended_capabilities_len,
2905 					    capab->extended_capabilities) ||
2906 				    nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
2907 					    capab->extended_capabilities_len,
2908 					    capab->extended_capabilities_mask))
2909 					goto nla_put_failure;
2910 
2911 				if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_MLO &&
2912 				    (nla_put_u16(msg,
2913 						 NL80211_ATTR_EML_CAPABILITY,
2914 						 capab->eml_capabilities) ||
2915 				     nla_put_u16(msg,
2916 						 NL80211_ATTR_MLD_CAPA_AND_OPS,
2917 						 capab->mld_capa_and_ops)))
2918 					goto nla_put_failure;
2919 
2920 				nla_nest_end(msg, nested_ext_capab);
2921 				if (state->split)
2922 					break;
2923 			}
2924 			nla_nest_end(msg, nested);
2925 			if (i < rdev->wiphy.num_iftype_ext_capab) {
2926 				state->capa_start = i + 1;
2927 				break;
2928 			}
2929 		}
2930 
2931 		if (nla_put_u32(msg, NL80211_ATTR_BANDS,
2932 				rdev->wiphy.nan_supported_bands))
2933 			goto nla_put_failure;
2934 
2935 		if (wiphy_ext_feature_isset(&rdev->wiphy,
2936 					    NL80211_EXT_FEATURE_TXQS)) {
2937 			struct cfg80211_txq_stats txqstats = {};
2938 			int res;
2939 
2940 			res = rdev_get_txq_stats(rdev, NULL, &txqstats);
2941 			if (!res &&
2942 			    !nl80211_put_txq_stats(msg, &txqstats,
2943 						   NL80211_ATTR_TXQ_STATS))
2944 				goto nla_put_failure;
2945 
2946 			if (nla_put_u32(msg, NL80211_ATTR_TXQ_LIMIT,
2947 					rdev->wiphy.txq_limit))
2948 				goto nla_put_failure;
2949 			if (nla_put_u32(msg, NL80211_ATTR_TXQ_MEMORY_LIMIT,
2950 					rdev->wiphy.txq_memory_limit))
2951 				goto nla_put_failure;
2952 			if (nla_put_u32(msg, NL80211_ATTR_TXQ_QUANTUM,
2953 					rdev->wiphy.txq_quantum))
2954 				goto nla_put_failure;
2955 		}
2956 
2957 		state->split_start++;
2958 		break;
2959 	case 14:
2960 		if (nl80211_send_pmsr_capa(rdev, msg))
2961 			goto nla_put_failure;
2962 
2963 		state->split_start++;
2964 		break;
2965 	case 15:
2966 		if (rdev->wiphy.akm_suites &&
2967 		    nla_put(msg, NL80211_ATTR_AKM_SUITES,
2968 			    sizeof(u32) * rdev->wiphy.n_akm_suites,
2969 			    rdev->wiphy.akm_suites))
2970 			goto nla_put_failure;
2971 
2972 		if (nl80211_put_iftype_akm_suites(rdev, msg))
2973 			goto nla_put_failure;
2974 
2975 		if (nl80211_put_tid_config_support(rdev, msg))
2976 			goto nla_put_failure;
2977 		state->split_start++;
2978 		break;
2979 	case 16:
2980 		if (nl80211_put_sar_specs(rdev, msg))
2981 			goto nla_put_failure;
2982 
2983 		if (nl80211_put_mbssid_support(&rdev->wiphy, msg))
2984 			goto nla_put_failure;
2985 
2986 		if (nla_put_u16(msg, NL80211_ATTR_MAX_NUM_AKM_SUITES,
2987 				rdev->wiphy.max_num_akm_suites))
2988 			goto nla_put_failure;
2989 
2990 		if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_MLO)
2991 			nla_put_flag(msg, NL80211_ATTR_MLO_SUPPORT);
2992 
2993 		if (rdev->wiphy.hw_timestamp_max_peers &&
2994 		    nla_put_u16(msg, NL80211_ATTR_MAX_HW_TIMESTAMP_PEERS,
2995 				rdev->wiphy.hw_timestamp_max_peers))
2996 			goto nla_put_failure;
2997 
2998 		/* done */
2999 		state->split_start = 0;
3000 		break;
3001 	}
3002  finish:
3003 	genlmsg_end(msg, hdr);
3004 	return 0;
3005 
3006  nla_put_failure:
3007 	genlmsg_cancel(msg, hdr);
3008 	return -EMSGSIZE;
3009 }
3010 
nl80211_dump_wiphy_parse(struct sk_buff * skb,struct netlink_callback * cb,struct nl80211_dump_wiphy_state * state)3011 static int nl80211_dump_wiphy_parse(struct sk_buff *skb,
3012 				    struct netlink_callback *cb,
3013 				    struct nl80211_dump_wiphy_state *state)
3014 {
3015 	struct nlattr **tb = kcalloc(NUM_NL80211_ATTR, sizeof(*tb), GFP_KERNEL);
3016 	int ret;
3017 
3018 	if (!tb)
3019 		return -ENOMEM;
3020 
3021 	ret = nlmsg_parse_deprecated(cb->nlh,
3022 				     GENL_HDRLEN + nl80211_fam.hdrsize,
3023 				     tb, nl80211_fam.maxattr,
3024 				     nl80211_policy, NULL);
3025 	/* ignore parse errors for backward compatibility */
3026 	if (ret) {
3027 		ret = 0;
3028 		goto out;
3029 	}
3030 
3031 	state->split = tb[NL80211_ATTR_SPLIT_WIPHY_DUMP];
3032 	if (tb[NL80211_ATTR_WIPHY])
3033 		state->filter_wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]);
3034 	if (tb[NL80211_ATTR_WDEV])
3035 		state->filter_wiphy = nla_get_u64(tb[NL80211_ATTR_WDEV]) >> 32;
3036 	if (tb[NL80211_ATTR_IFINDEX]) {
3037 		struct net_device *netdev;
3038 		struct cfg80211_registered_device *rdev;
3039 		int ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
3040 
3041 		netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3042 		if (!netdev) {
3043 			ret = -ENODEV;
3044 			goto out;
3045 		}
3046 		if (netdev->ieee80211_ptr) {
3047 			rdev = wiphy_to_rdev(
3048 				netdev->ieee80211_ptr->wiphy);
3049 			state->filter_wiphy = rdev->wiphy_idx;
3050 		}
3051 	}
3052 
3053 	ret = 0;
3054 out:
3055 	kfree(tb);
3056 	return ret;
3057 }
3058 
nl80211_dump_wiphy(struct sk_buff * skb,struct netlink_callback * cb)3059 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
3060 {
3061 	int idx = 0, ret;
3062 	struct nl80211_dump_wiphy_state *state = (void *)cb->args[0];
3063 	struct cfg80211_registered_device *rdev;
3064 
3065 	rtnl_lock();
3066 	if (!state) {
3067 		state = kzalloc(sizeof(*state), GFP_KERNEL);
3068 		if (!state) {
3069 			rtnl_unlock();
3070 			return -ENOMEM;
3071 		}
3072 		state->filter_wiphy = -1;
3073 		ret = nl80211_dump_wiphy_parse(skb, cb, state);
3074 		if (ret) {
3075 			kfree(state);
3076 			rtnl_unlock();
3077 			return ret;
3078 		}
3079 		cb->args[0] = (long)state;
3080 	}
3081 
3082 	list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
3083 		if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
3084 			continue;
3085 		if (++idx <= state->start)
3086 			continue;
3087 		if (state->filter_wiphy != -1 &&
3088 		    state->filter_wiphy != rdev->wiphy_idx)
3089 			continue;
3090 		wiphy_lock(&rdev->wiphy);
3091 		/* attempt to fit multiple wiphy data chunks into the skb */
3092 		do {
3093 			ret = nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY,
3094 						 skb,
3095 						 NETLINK_CB(cb->skb).portid,
3096 						 cb->nlh->nlmsg_seq,
3097 						 NLM_F_MULTI, state);
3098 			if (ret < 0) {
3099 				/*
3100 				 * If sending the wiphy data didn't fit (ENOBUFS
3101 				 * or EMSGSIZE returned), this SKB is still
3102 				 * empty (so it's not too big because another
3103 				 * wiphy dataset is already in the skb) and
3104 				 * we've not tried to adjust the dump allocation
3105 				 * yet ... then adjust the alloc size to be
3106 				 * bigger, and return 1 but with the empty skb.
3107 				 * This results in an empty message being RX'ed
3108 				 * in userspace, but that is ignored.
3109 				 *
3110 				 * We can then retry with the larger buffer.
3111 				 */
3112 				if ((ret == -ENOBUFS || ret == -EMSGSIZE) &&
3113 				    !skb->len && !state->split &&
3114 				    cb->min_dump_alloc < 4096) {
3115 					cb->min_dump_alloc = 4096;
3116 					state->split_start = 0;
3117 					wiphy_unlock(&rdev->wiphy);
3118 					rtnl_unlock();
3119 					return 1;
3120 				}
3121 				idx--;
3122 				break;
3123 			}
3124 		} while (state->split_start > 0);
3125 		wiphy_unlock(&rdev->wiphy);
3126 		break;
3127 	}
3128 	rtnl_unlock();
3129 
3130 	state->start = idx;
3131 
3132 	return skb->len;
3133 }
3134 
nl80211_dump_wiphy_done(struct netlink_callback * cb)3135 static int nl80211_dump_wiphy_done(struct netlink_callback *cb)
3136 {
3137 	kfree((void *)cb->args[0]);
3138 	return 0;
3139 }
3140 
nl80211_get_wiphy(struct sk_buff * skb,struct genl_info * info)3141 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
3142 {
3143 	struct sk_buff *msg;
3144 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
3145 	struct nl80211_dump_wiphy_state state = {};
3146 
3147 	msg = nlmsg_new(4096, GFP_KERNEL);
3148 	if (!msg)
3149 		return -ENOMEM;
3150 
3151 	if (nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY, msg,
3152 			       info->snd_portid, info->snd_seq, 0,
3153 			       &state) < 0) {
3154 		nlmsg_free(msg);
3155 		return -ENOBUFS;
3156 	}
3157 
3158 	return genlmsg_reply(msg, info);
3159 }
3160 
3161 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
3162 	[NL80211_TXQ_ATTR_QUEUE]		= { .type = NLA_U8 },
3163 	[NL80211_TXQ_ATTR_TXOP]			= { .type = NLA_U16 },
3164 	[NL80211_TXQ_ATTR_CWMIN]		= { .type = NLA_U16 },
3165 	[NL80211_TXQ_ATTR_CWMAX]		= { .type = NLA_U16 },
3166 	[NL80211_TXQ_ATTR_AIFS]			= { .type = NLA_U8 },
3167 };
3168 
parse_txq_params(struct nlattr * tb[],struct ieee80211_txq_params * txq_params)3169 static int parse_txq_params(struct nlattr *tb[],
3170 			    struct ieee80211_txq_params *txq_params)
3171 {
3172 	u8 ac;
3173 
3174 	if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
3175 	    !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
3176 	    !tb[NL80211_TXQ_ATTR_AIFS])
3177 		return -EINVAL;
3178 
3179 	ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
3180 	txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
3181 	txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
3182 	txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
3183 	txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
3184 
3185 	if (ac >= NL80211_NUM_ACS)
3186 		return -EINVAL;
3187 	txq_params->ac = array_index_nospec(ac, NL80211_NUM_ACS);
3188 	return 0;
3189 }
3190 
nl80211_can_set_dev_channel(struct wireless_dev * wdev)3191 static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
3192 {
3193 	/*
3194 	 * You can only set the channel explicitly for some interfaces,
3195 	 * most have their channel managed via their respective
3196 	 * "establish a connection" command (connect, join, ...)
3197 	 *
3198 	 * For AP/GO and mesh mode, the channel can be set with the
3199 	 * channel userspace API, but is only stored and passed to the
3200 	 * low-level driver when the AP starts or the mesh is joined.
3201 	 * This is for backward compatibility, userspace can also give
3202 	 * the channel in the start-ap or join-mesh commands instead.
3203 	 *
3204 	 * Monitors are special as they are normally slaved to
3205 	 * whatever else is going on, so they have their own special
3206 	 * operation to set the monitor channel if possible.
3207 	 */
3208 	return !wdev ||
3209 		wdev->iftype == NL80211_IFTYPE_AP ||
3210 		wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
3211 		wdev->iftype == NL80211_IFTYPE_MONITOR ||
3212 		wdev->iftype == NL80211_IFTYPE_P2P_GO;
3213 }
3214 
nl80211_parse_punct_bitmap(struct cfg80211_registered_device * rdev,struct genl_info * info,const struct cfg80211_chan_def * chandef,u16 * punct_bitmap)3215 static int nl80211_parse_punct_bitmap(struct cfg80211_registered_device *rdev,
3216 				      struct genl_info *info,
3217 				      const struct cfg80211_chan_def *chandef,
3218 				      u16 *punct_bitmap)
3219 {
3220 	if (!wiphy_ext_feature_isset(&rdev->wiphy, NL80211_EXT_FEATURE_PUNCT))
3221 		return -EINVAL;
3222 
3223 	*punct_bitmap = nla_get_u32(info->attrs[NL80211_ATTR_PUNCT_BITMAP]);
3224 	if (!cfg80211_valid_disable_subchannel_bitmap(punct_bitmap, chandef))
3225 		return -EINVAL;
3226 
3227 	return 0;
3228 }
3229 
nl80211_parse_chandef(struct cfg80211_registered_device * rdev,struct genl_info * info,struct cfg80211_chan_def * chandef)3230 int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
3231 			  struct genl_info *info,
3232 			  struct cfg80211_chan_def *chandef)
3233 {
3234 	struct netlink_ext_ack *extack = info->extack;
3235 	struct nlattr **attrs = info->attrs;
3236 	u32 control_freq;
3237 
3238 	if (!attrs[NL80211_ATTR_WIPHY_FREQ]) {
3239 		NL_SET_ERR_MSG_ATTR(extack, attrs[NL80211_ATTR_WIPHY_FREQ],
3240 				    "Frequency is missing");
3241 		return -EINVAL;
3242 	}
3243 
3244 	control_freq = MHZ_TO_KHZ(
3245 			nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3246 	if (info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET])
3247 		control_freq +=
3248 		    nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET]);
3249 
3250 	memset(chandef, 0, sizeof(*chandef));
3251 	chandef->chan = ieee80211_get_channel_khz(&rdev->wiphy, control_freq);
3252 	chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
3253 	chandef->center_freq1 = KHZ_TO_MHZ(control_freq);
3254 	chandef->freq1_offset = control_freq % 1000;
3255 	chandef->center_freq2 = 0;
3256 
3257 	/* Primary channel not allowed */
3258 	if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED) {
3259 		NL_SET_ERR_MSG_ATTR(extack, attrs[NL80211_ATTR_WIPHY_FREQ],
3260 				    "Channel is disabled");
3261 		return -EINVAL;
3262 	}
3263 
3264 	if (attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
3265 		enum nl80211_channel_type chantype;
3266 
3267 		chantype = nla_get_u32(attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
3268 
3269 		switch (chantype) {
3270 		case NL80211_CHAN_NO_HT:
3271 		case NL80211_CHAN_HT20:
3272 		case NL80211_CHAN_HT40PLUS:
3273 		case NL80211_CHAN_HT40MINUS:
3274 			cfg80211_chandef_create(chandef, chandef->chan,
3275 						chantype);
3276 			/* user input for center_freq is incorrect */
3277 			if (attrs[NL80211_ATTR_CENTER_FREQ1] &&
3278 			    chandef->center_freq1 != nla_get_u32(attrs[NL80211_ATTR_CENTER_FREQ1])) {
3279 				NL_SET_ERR_MSG_ATTR(extack,
3280 						    attrs[NL80211_ATTR_CENTER_FREQ1],
3281 						    "bad center frequency 1");
3282 				return -EINVAL;
3283 			}
3284 			/* center_freq2 must be zero */
3285 			if (attrs[NL80211_ATTR_CENTER_FREQ2] &&
3286 			    nla_get_u32(attrs[NL80211_ATTR_CENTER_FREQ2])) {
3287 				NL_SET_ERR_MSG_ATTR(extack,
3288 						    attrs[NL80211_ATTR_CENTER_FREQ2],
3289 						    "center frequency 2 can't be used");
3290 				return -EINVAL;
3291 			}
3292 			break;
3293 		default:
3294 			NL_SET_ERR_MSG_ATTR(extack,
3295 					    attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE],
3296 					    "invalid channel type");
3297 			return -EINVAL;
3298 		}
3299 	} else if (attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
3300 		chandef->width =
3301 			nla_get_u32(attrs[NL80211_ATTR_CHANNEL_WIDTH]);
3302 		if (chandef->chan->band == NL80211_BAND_S1GHZ) {
3303 			/* User input error for channel width doesn't match channel  */
3304 			if (chandef->width != ieee80211_s1g_channel_width(chandef->chan)) {
3305 				NL_SET_ERR_MSG_ATTR(extack,
3306 						    attrs[NL80211_ATTR_CHANNEL_WIDTH],
3307 						    "bad channel width");
3308 				return -EINVAL;
3309 			}
3310 		}
3311 		if (attrs[NL80211_ATTR_CENTER_FREQ1]) {
3312 			chandef->center_freq1 =
3313 				nla_get_u32(attrs[NL80211_ATTR_CENTER_FREQ1]);
3314 			if (attrs[NL80211_ATTR_CENTER_FREQ1_OFFSET])
3315 				chandef->freq1_offset = nla_get_u32(
3316 				      attrs[NL80211_ATTR_CENTER_FREQ1_OFFSET]);
3317 			else
3318 				chandef->freq1_offset = 0;
3319 		}
3320 		if (attrs[NL80211_ATTR_CENTER_FREQ2])
3321 			chandef->center_freq2 =
3322 				nla_get_u32(attrs[NL80211_ATTR_CENTER_FREQ2]);
3323 	}
3324 
3325 	if (info->attrs[NL80211_ATTR_WIPHY_EDMG_CHANNELS]) {
3326 		chandef->edmg.channels =
3327 		      nla_get_u8(info->attrs[NL80211_ATTR_WIPHY_EDMG_CHANNELS]);
3328 
3329 		if (info->attrs[NL80211_ATTR_WIPHY_EDMG_BW_CONFIG])
3330 			chandef->edmg.bw_config =
3331 		     nla_get_u8(info->attrs[NL80211_ATTR_WIPHY_EDMG_BW_CONFIG]);
3332 	} else {
3333 		chandef->edmg.bw_config = 0;
3334 		chandef->edmg.channels = 0;
3335 	}
3336 
3337 	if (!cfg80211_chandef_valid(chandef)) {
3338 		NL_SET_ERR_MSG(extack, "invalid channel definition");
3339 		return -EINVAL;
3340 	}
3341 
3342 	if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
3343 				     IEEE80211_CHAN_DISABLED)) {
3344 		NL_SET_ERR_MSG(extack, "(extension) channel is disabled");
3345 		return -EINVAL;
3346 	}
3347 
3348 	if ((chandef->width == NL80211_CHAN_WIDTH_5 ||
3349 	     chandef->width == NL80211_CHAN_WIDTH_10) &&
3350 	    !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ)) {
3351 		NL_SET_ERR_MSG(extack, "5/10 MHz not supported");
3352 		return -EINVAL;
3353 	}
3354 
3355 	return 0;
3356 }
3357 
__nl80211_set_channel(struct cfg80211_registered_device * rdev,struct net_device * dev,struct genl_info * info,int _link_id)3358 static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
3359 				 struct net_device *dev,
3360 				 struct genl_info *info,
3361 				 int _link_id)
3362 {
3363 	struct cfg80211_chan_def chandef;
3364 	int result;
3365 	enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
3366 	struct wireless_dev *wdev = NULL;
3367 	int link_id = _link_id;
3368 
3369 	if (dev)
3370 		wdev = dev->ieee80211_ptr;
3371 	if (!nl80211_can_set_dev_channel(wdev))
3372 		return -EOPNOTSUPP;
3373 	if (wdev)
3374 		iftype = wdev->iftype;
3375 
3376 	if (link_id < 0) {
3377 		if (wdev && wdev->valid_links)
3378 			return -EINVAL;
3379 		link_id = 0;
3380 	}
3381 
3382 	result = nl80211_parse_chandef(rdev, info, &chandef);
3383 	if (result)
3384 		return result;
3385 
3386 	switch (iftype) {
3387 	case NL80211_IFTYPE_AP:
3388 	case NL80211_IFTYPE_P2P_GO:
3389 		if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef,
3390 						   iftype))
3391 			return -EINVAL;
3392 		if (wdev->links[link_id].ap.beacon_interval) {
3393 			struct ieee80211_channel *cur_chan;
3394 
3395 			if (!dev || !rdev->ops->set_ap_chanwidth ||
3396 			    !(rdev->wiphy.features &
3397 			      NL80211_FEATURE_AP_MODE_CHAN_WIDTH_CHANGE))
3398 				return -EBUSY;
3399 
3400 			/* Only allow dynamic channel width changes */
3401 			cur_chan = wdev->links[link_id].ap.chandef.chan;
3402 			if (chandef.chan != cur_chan)
3403 				return -EBUSY;
3404 
3405 			/* only allow this for regular channel widths */
3406 			switch (wdev->links[link_id].ap.chandef.width) {
3407 			case NL80211_CHAN_WIDTH_20_NOHT:
3408 			case NL80211_CHAN_WIDTH_20:
3409 			case NL80211_CHAN_WIDTH_40:
3410 			case NL80211_CHAN_WIDTH_80:
3411 			case NL80211_CHAN_WIDTH_80P80:
3412 			case NL80211_CHAN_WIDTH_160:
3413 			case NL80211_CHAN_WIDTH_320:
3414 				break;
3415 			default:
3416 				return -EINVAL;
3417 			}
3418 
3419 			switch (chandef.width) {
3420 			case NL80211_CHAN_WIDTH_20_NOHT:
3421 			case NL80211_CHAN_WIDTH_20:
3422 			case NL80211_CHAN_WIDTH_40:
3423 			case NL80211_CHAN_WIDTH_80:
3424 			case NL80211_CHAN_WIDTH_80P80:
3425 			case NL80211_CHAN_WIDTH_160:
3426 			case NL80211_CHAN_WIDTH_320:
3427 				break;
3428 			default:
3429 				return -EINVAL;
3430 			}
3431 
3432 			result = rdev_set_ap_chanwidth(rdev, dev, link_id,
3433 						       &chandef);
3434 			if (result)
3435 				return result;
3436 			wdev->links[link_id].ap.chandef = chandef;
3437 		} else {
3438 			wdev->u.ap.preset_chandef = chandef;
3439 		}
3440 		return 0;
3441 	case NL80211_IFTYPE_MESH_POINT:
3442 		return cfg80211_set_mesh_channel(rdev, wdev, &chandef);
3443 	case NL80211_IFTYPE_MONITOR:
3444 		return cfg80211_set_monitor_channel(rdev, &chandef);
3445 	default:
3446 		break;
3447 	}
3448 
3449 	return -EINVAL;
3450 }
3451 
nl80211_set_channel(struct sk_buff * skb,struct genl_info * info)3452 static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
3453 {
3454 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
3455 	int link_id = nl80211_link_id_or_invalid(info->attrs);
3456 	struct net_device *netdev = info->user_ptr[1];
3457 	int ret;
3458 
3459 	wdev_lock(netdev->ieee80211_ptr);
3460 	ret = __nl80211_set_channel(rdev, netdev, info, link_id);
3461 	wdev_unlock(netdev->ieee80211_ptr);
3462 
3463 	return ret;
3464 }
3465 
nl80211_set_wiphy(struct sk_buff * skb,struct genl_info * info)3466 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
3467 {
3468 	struct cfg80211_registered_device *rdev = NULL;
3469 	struct net_device *netdev = NULL;
3470 	struct wireless_dev *wdev;
3471 	int result = 0, rem_txq_params = 0;
3472 	struct nlattr *nl_txq_params;
3473 	u32 changed;
3474 	u8 retry_short = 0, retry_long = 0;
3475 	u32 frag_threshold = 0, rts_threshold = 0;
3476 	u8 coverage_class = 0;
3477 	u32 txq_limit = 0, txq_memory_limit = 0, txq_quantum = 0;
3478 
3479 	rtnl_lock();
3480 	/*
3481 	 * Try to find the wiphy and netdev. Normally this
3482 	 * function shouldn't need the netdev, but this is
3483 	 * done for backward compatibility -- previously
3484 	 * setting the channel was done per wiphy, but now
3485 	 * it is per netdev. Previous userland like hostapd
3486 	 * also passed a netdev to set_wiphy, so that it is
3487 	 * possible to let that go to the right netdev!
3488 	 */
3489 
3490 	if (info->attrs[NL80211_ATTR_IFINDEX]) {
3491 		int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
3492 
3493 		netdev = __dev_get_by_index(genl_info_net(info), ifindex);
3494 		if (netdev && netdev->ieee80211_ptr)
3495 			rdev = wiphy_to_rdev(netdev->ieee80211_ptr->wiphy);
3496 		else
3497 			netdev = NULL;
3498 	}
3499 
3500 	if (!netdev) {
3501 		rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
3502 						  info->attrs);
3503 		if (IS_ERR(rdev)) {
3504 			rtnl_unlock();
3505 			return PTR_ERR(rdev);
3506 		}
3507 		wdev = NULL;
3508 		netdev = NULL;
3509 		result = 0;
3510 	} else
3511 		wdev = netdev->ieee80211_ptr;
3512 
3513 	wiphy_lock(&rdev->wiphy);
3514 
3515 	/*
3516 	 * end workaround code, by now the rdev is available
3517 	 * and locked, and wdev may or may not be NULL.
3518 	 */
3519 
3520 	if (info->attrs[NL80211_ATTR_WIPHY_NAME])
3521 		result = cfg80211_dev_rename(
3522 			rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
3523 	rtnl_unlock();
3524 
3525 	if (result)
3526 		goto out;
3527 
3528 	if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
3529 		struct ieee80211_txq_params txq_params;
3530 		struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
3531 
3532 		if (!rdev->ops->set_txq_params) {
3533 			result = -EOPNOTSUPP;
3534 			goto out;
3535 		}
3536 
3537 		if (!netdev) {
3538 			result = -EINVAL;
3539 			goto out;
3540 		}
3541 
3542 		if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3543 		    netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
3544 			result = -EINVAL;
3545 			goto out;
3546 		}
3547 
3548 		if (!netif_running(netdev)) {
3549 			result = -ENETDOWN;
3550 			goto out;
3551 		}
3552 
3553 		nla_for_each_nested(nl_txq_params,
3554 				    info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
3555 				    rem_txq_params) {
3556 			result = nla_parse_nested_deprecated(tb,
3557 							     NL80211_TXQ_ATTR_MAX,
3558 							     nl_txq_params,
3559 							     txq_params_policy,
3560 							     info->extack);
3561 			if (result)
3562 				goto out;
3563 			result = parse_txq_params(tb, &txq_params);
3564 			if (result)
3565 				goto out;
3566 
3567 			txq_params.link_id =
3568 				nl80211_link_id_or_invalid(info->attrs);
3569 
3570 			wdev_lock(netdev->ieee80211_ptr);
3571 			if (txq_params.link_id >= 0 &&
3572 			    !(netdev->ieee80211_ptr->valid_links &
3573 			      BIT(txq_params.link_id)))
3574 				result = -ENOLINK;
3575 			else if (txq_params.link_id >= 0 &&
3576 				 !netdev->ieee80211_ptr->valid_links)
3577 				result = -EINVAL;
3578 			else
3579 				result = rdev_set_txq_params(rdev, netdev,
3580 							     &txq_params);
3581 			wdev_unlock(netdev->ieee80211_ptr);
3582 			if (result)
3583 				goto out;
3584 		}
3585 	}
3586 
3587 	if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
3588 		int link_id = nl80211_link_id_or_invalid(info->attrs);
3589 
3590 		if (wdev) {
3591 			wdev_lock(wdev);
3592 			result = __nl80211_set_channel(
3593 				rdev,
3594 				nl80211_can_set_dev_channel(wdev) ? netdev : NULL,
3595 				info, link_id);
3596 			wdev_unlock(wdev);
3597 		} else {
3598 			result = __nl80211_set_channel(rdev, netdev, info, link_id);
3599 		}
3600 
3601 		if (result)
3602 			goto out;
3603 	}
3604 
3605 	if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
3606 		struct wireless_dev *txp_wdev = wdev;
3607 		enum nl80211_tx_power_setting type;
3608 		int idx, mbm = 0;
3609 
3610 		if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
3611 			txp_wdev = NULL;
3612 
3613 		if (!rdev->ops->set_tx_power) {
3614 			result = -EOPNOTSUPP;
3615 			goto out;
3616 		}
3617 
3618 		idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
3619 		type = nla_get_u32(info->attrs[idx]);
3620 
3621 		if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
3622 		    (type != NL80211_TX_POWER_AUTOMATIC)) {
3623 			result = -EINVAL;
3624 			goto out;
3625 		}
3626 
3627 		if (type != NL80211_TX_POWER_AUTOMATIC) {
3628 			idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
3629 			mbm = nla_get_u32(info->attrs[idx]);
3630 		}
3631 
3632 		result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
3633 		if (result)
3634 			goto out;
3635 	}
3636 
3637 	if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
3638 	    info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
3639 		u32 tx_ant, rx_ant;
3640 
3641 		if ((!rdev->wiphy.available_antennas_tx &&
3642 		     !rdev->wiphy.available_antennas_rx) ||
3643 		    !rdev->ops->set_antenna) {
3644 			result = -EOPNOTSUPP;
3645 			goto out;
3646 		}
3647 
3648 		tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
3649 		rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
3650 
3651 		/* reject antenna configurations which don't match the
3652 		 * available antenna masks, except for the "all" mask */
3653 		if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
3654 		    (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
3655 			result = -EINVAL;
3656 			goto out;
3657 		}
3658 
3659 		tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
3660 		rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
3661 
3662 		result = rdev_set_antenna(rdev, tx_ant, rx_ant);
3663 		if (result)
3664 			goto out;
3665 	}
3666 
3667 	changed = 0;
3668 
3669 	if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
3670 		retry_short = nla_get_u8(
3671 			info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
3672 
3673 		changed |= WIPHY_PARAM_RETRY_SHORT;
3674 	}
3675 
3676 	if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
3677 		retry_long = nla_get_u8(
3678 			info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
3679 
3680 		changed |= WIPHY_PARAM_RETRY_LONG;
3681 	}
3682 
3683 	if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
3684 		frag_threshold = nla_get_u32(
3685 			info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
3686 		if (frag_threshold < 256) {
3687 			result = -EINVAL;
3688 			goto out;
3689 		}
3690 
3691 		if (frag_threshold != (u32) -1) {
3692 			/*
3693 			 * Fragments (apart from the last one) are required to
3694 			 * have even length. Make the fragmentation code
3695 			 * simpler by stripping LSB should someone try to use
3696 			 * odd threshold value.
3697 			 */
3698 			frag_threshold &= ~0x1;
3699 		}
3700 		changed |= WIPHY_PARAM_FRAG_THRESHOLD;
3701 	}
3702 
3703 	if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
3704 		rts_threshold = nla_get_u32(
3705 			info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
3706 		changed |= WIPHY_PARAM_RTS_THRESHOLD;
3707 	}
3708 
3709 	if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
3710 		if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK]) {
3711 			result = -EINVAL;
3712 			goto out;
3713 		}
3714 
3715 		coverage_class = nla_get_u8(
3716 			info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
3717 		changed |= WIPHY_PARAM_COVERAGE_CLASS;
3718 	}
3719 
3720 	if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK]) {
3721 		if (!(rdev->wiphy.features & NL80211_FEATURE_ACKTO_ESTIMATION)) {
3722 			result = -EOPNOTSUPP;
3723 			goto out;
3724 		}
3725 
3726 		changed |= WIPHY_PARAM_DYN_ACK;
3727 	}
3728 
3729 	if (info->attrs[NL80211_ATTR_TXQ_LIMIT]) {
3730 		if (!wiphy_ext_feature_isset(&rdev->wiphy,
3731 					     NL80211_EXT_FEATURE_TXQS)) {
3732 			result = -EOPNOTSUPP;
3733 			goto out;
3734 		}
3735 		txq_limit = nla_get_u32(
3736 			info->attrs[NL80211_ATTR_TXQ_LIMIT]);
3737 		changed |= WIPHY_PARAM_TXQ_LIMIT;
3738 	}
3739 
3740 	if (info->attrs[NL80211_ATTR_TXQ_MEMORY_LIMIT]) {
3741 		if (!wiphy_ext_feature_isset(&rdev->wiphy,
3742 					     NL80211_EXT_FEATURE_TXQS)) {
3743 			result = -EOPNOTSUPP;
3744 			goto out;
3745 		}
3746 		txq_memory_limit = nla_get_u32(
3747 			info->attrs[NL80211_ATTR_TXQ_MEMORY_LIMIT]);
3748 		changed |= WIPHY_PARAM_TXQ_MEMORY_LIMIT;
3749 	}
3750 
3751 	if (info->attrs[NL80211_ATTR_TXQ_QUANTUM]) {
3752 		if (!wiphy_ext_feature_isset(&rdev->wiphy,
3753 					     NL80211_EXT_FEATURE_TXQS)) {
3754 			result = -EOPNOTSUPP;
3755 			goto out;
3756 		}
3757 		txq_quantum = nla_get_u32(
3758 			info->attrs[NL80211_ATTR_TXQ_QUANTUM]);
3759 		changed |= WIPHY_PARAM_TXQ_QUANTUM;
3760 	}
3761 
3762 	if (changed) {
3763 		u8 old_retry_short, old_retry_long;
3764 		u32 old_frag_threshold, old_rts_threshold;
3765 		u8 old_coverage_class;
3766 		u32 old_txq_limit, old_txq_memory_limit, old_txq_quantum;
3767 
3768 		if (!rdev->ops->set_wiphy_params) {
3769 			result = -EOPNOTSUPP;
3770 			goto out;
3771 		}
3772 
3773 		old_retry_short = rdev->wiphy.retry_short;
3774 		old_retry_long = rdev->wiphy.retry_long;
3775 		old_frag_threshold = rdev->wiphy.frag_threshold;
3776 		old_rts_threshold = rdev->wiphy.rts_threshold;
3777 		old_coverage_class = rdev->wiphy.coverage_class;
3778 		old_txq_limit = rdev->wiphy.txq_limit;
3779 		old_txq_memory_limit = rdev->wiphy.txq_memory_limit;
3780 		old_txq_quantum = rdev->wiphy.txq_quantum;
3781 
3782 		if (changed & WIPHY_PARAM_RETRY_SHORT)
3783 			rdev->wiphy.retry_short = retry_short;
3784 		if (changed & WIPHY_PARAM_RETRY_LONG)
3785 			rdev->wiphy.retry_long = retry_long;
3786 		if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
3787 			rdev->wiphy.frag_threshold = frag_threshold;
3788 		if (changed & WIPHY_PARAM_RTS_THRESHOLD)
3789 			rdev->wiphy.rts_threshold = rts_threshold;
3790 		if (changed & WIPHY_PARAM_COVERAGE_CLASS)
3791 			rdev->wiphy.coverage_class = coverage_class;
3792 		if (changed & WIPHY_PARAM_TXQ_LIMIT)
3793 			rdev->wiphy.txq_limit = txq_limit;
3794 		if (changed & WIPHY_PARAM_TXQ_MEMORY_LIMIT)
3795 			rdev->wiphy.txq_memory_limit = txq_memory_limit;
3796 		if (changed & WIPHY_PARAM_TXQ_QUANTUM)
3797 			rdev->wiphy.txq_quantum = txq_quantum;
3798 
3799 		result = rdev_set_wiphy_params(rdev, changed);
3800 		if (result) {
3801 			rdev->wiphy.retry_short = old_retry_short;
3802 			rdev->wiphy.retry_long = old_retry_long;
3803 			rdev->wiphy.frag_threshold = old_frag_threshold;
3804 			rdev->wiphy.rts_threshold = old_rts_threshold;
3805 			rdev->wiphy.coverage_class = old_coverage_class;
3806 			rdev->wiphy.txq_limit = old_txq_limit;
3807 			rdev->wiphy.txq_memory_limit = old_txq_memory_limit;
3808 			rdev->wiphy.txq_quantum = old_txq_quantum;
3809 			goto out;
3810 		}
3811 	}
3812 
3813 	result = 0;
3814 
3815 out:
3816 	wiphy_unlock(&rdev->wiphy);
3817 	return result;
3818 }
3819 
nl80211_send_chandef(struct sk_buff * msg,const struct cfg80211_chan_def * chandef)3820 int nl80211_send_chandef(struct sk_buff *msg, const struct cfg80211_chan_def *chandef)
3821 {
3822 	if (WARN_ON(!cfg80211_chandef_valid(chandef)))
3823 		return -EINVAL;
3824 
3825 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
3826 			chandef->chan->center_freq))
3827 		return -ENOBUFS;
3828 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ_OFFSET,
3829 			chandef->chan->freq_offset))
3830 		return -ENOBUFS;
3831 	switch (chandef->width) {
3832 	case NL80211_CHAN_WIDTH_20_NOHT:
3833 	case NL80211_CHAN_WIDTH_20:
3834 	case NL80211_CHAN_WIDTH_40:
3835 		if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
3836 				cfg80211_get_chandef_type(chandef)))
3837 			return -ENOBUFS;
3838 		break;
3839 	default:
3840 		break;
3841 	}
3842 	if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
3843 		return -ENOBUFS;
3844 	if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
3845 		return -ENOBUFS;
3846 	if (chandef->center_freq2 &&
3847 	    nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
3848 		return -ENOBUFS;
3849 	return 0;
3850 }
3851 EXPORT_SYMBOL(nl80211_send_chandef);
3852 
nl80211_send_iface(struct sk_buff * msg,u32 portid,u32 seq,int flags,struct cfg80211_registered_device * rdev,struct wireless_dev * wdev,enum nl80211_commands cmd)3853 static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
3854 			      struct cfg80211_registered_device *rdev,
3855 			      struct wireless_dev *wdev,
3856 			      enum nl80211_commands cmd)
3857 {
3858 	struct net_device *dev = wdev->netdev;
3859 	void *hdr;
3860 
3861 	WARN_ON(cmd != NL80211_CMD_NEW_INTERFACE &&
3862 		cmd != NL80211_CMD_DEL_INTERFACE &&
3863 		cmd != NL80211_CMD_SET_INTERFACE);
3864 
3865 	hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
3866 	if (!hdr)
3867 		return -1;
3868 
3869 	if (dev &&
3870 	    (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3871 	     nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
3872 		goto nla_put_failure;
3873 
3874 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
3875 	    nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
3876 	    nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
3877 			      NL80211_ATTR_PAD) ||
3878 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
3879 	    nla_put_u32(msg, NL80211_ATTR_GENERATION,
3880 			rdev->devlist_generation ^
3881 			(cfg80211_rdev_list_generation << 2)) ||
3882 	    nla_put_u8(msg, NL80211_ATTR_4ADDR, wdev->use_4addr))
3883 		goto nla_put_failure;
3884 
3885 	if (rdev->ops->get_channel && !wdev->valid_links) {
3886 		struct cfg80211_chan_def chandef = {};
3887 		int ret;
3888 
3889 		ret = rdev_get_channel(rdev, wdev, 0, &chandef);
3890 		if (ret == 0 && nl80211_send_chandef(msg, &chandef))
3891 			goto nla_put_failure;
3892 	}
3893 
3894 	if (rdev->ops->get_tx_power) {
3895 		int dbm, ret;
3896 
3897 		ret = rdev_get_tx_power(rdev, wdev, &dbm);
3898 		if (ret == 0 &&
3899 		    nla_put_u32(msg, NL80211_ATTR_WIPHY_TX_POWER_LEVEL,
3900 				DBM_TO_MBM(dbm)))
3901 			goto nla_put_failure;
3902 	}
3903 
3904 	wdev_lock(wdev);
3905 	switch (wdev->iftype) {
3906 	case NL80211_IFTYPE_AP:
3907 	case NL80211_IFTYPE_P2P_GO:
3908 		if (wdev->u.ap.ssid_len &&
3909 		    nla_put(msg, NL80211_ATTR_SSID, wdev->u.ap.ssid_len,
3910 			    wdev->u.ap.ssid))
3911 			goto nla_put_failure_locked;
3912 		break;
3913 	case NL80211_IFTYPE_STATION:
3914 	case NL80211_IFTYPE_P2P_CLIENT:
3915 		if (wdev->u.client.ssid_len &&
3916 		    nla_put(msg, NL80211_ATTR_SSID, wdev->u.client.ssid_len,
3917 			    wdev->u.client.ssid))
3918 			goto nla_put_failure_locked;
3919 		break;
3920 	case NL80211_IFTYPE_ADHOC:
3921 		if (wdev->u.ibss.ssid_len &&
3922 		    nla_put(msg, NL80211_ATTR_SSID, wdev->u.ibss.ssid_len,
3923 			    wdev->u.ibss.ssid))
3924 			goto nla_put_failure_locked;
3925 		break;
3926 	default:
3927 		/* nothing */
3928 		break;
3929 	}
3930 	wdev_unlock(wdev);
3931 
3932 	if (rdev->ops->get_txq_stats) {
3933 		struct cfg80211_txq_stats txqstats = {};
3934 		int ret = rdev_get_txq_stats(rdev, wdev, &txqstats);
3935 
3936 		if (ret == 0 &&
3937 		    !nl80211_put_txq_stats(msg, &txqstats,
3938 					   NL80211_ATTR_TXQ_STATS))
3939 			goto nla_put_failure;
3940 	}
3941 
3942 	if (wdev->valid_links) {
3943 		unsigned int link_id;
3944 		struct nlattr *links = nla_nest_start(msg,
3945 						      NL80211_ATTR_MLO_LINKS);
3946 
3947 		if (!links)
3948 			goto nla_put_failure;
3949 
3950 		for_each_valid_link(wdev, link_id) {
3951 			struct nlattr *link = nla_nest_start(msg, link_id + 1);
3952 			struct cfg80211_chan_def chandef = {};
3953 			int ret;
3954 
3955 			if (!link)
3956 				goto nla_put_failure;
3957 
3958 			if (nla_put_u8(msg, NL80211_ATTR_MLO_LINK_ID, link_id))
3959 				goto nla_put_failure;
3960 			if (nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN,
3961 				    wdev->links[link_id].addr))
3962 				goto nla_put_failure;
3963 
3964 			ret = rdev_get_channel(rdev, wdev, link_id, &chandef);
3965 			if (ret == 0 && nl80211_send_chandef(msg, &chandef))
3966 				goto nla_put_failure;
3967 
3968 			nla_nest_end(msg, link);
3969 		}
3970 
3971 		nla_nest_end(msg, links);
3972 	}
3973 
3974 	genlmsg_end(msg, hdr);
3975 	return 0;
3976 
3977  nla_put_failure_locked:
3978 	wdev_unlock(wdev);
3979  nla_put_failure:
3980 	genlmsg_cancel(msg, hdr);
3981 	return -EMSGSIZE;
3982 }
3983 
nl80211_dump_interface(struct sk_buff * skb,struct netlink_callback * cb)3984 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
3985 {
3986 	int wp_idx = 0;
3987 	int if_idx = 0;
3988 	int wp_start = cb->args[0];
3989 	int if_start = cb->args[1];
3990 	int filter_wiphy = -1;
3991 	struct cfg80211_registered_device *rdev;
3992 	struct wireless_dev *wdev;
3993 	int ret;
3994 
3995 	rtnl_lock();
3996 	if (!cb->args[2]) {
3997 		struct nl80211_dump_wiphy_state state = {
3998 			.filter_wiphy = -1,
3999 		};
4000 
4001 		ret = nl80211_dump_wiphy_parse(skb, cb, &state);
4002 		if (ret)
4003 			goto out_unlock;
4004 
4005 		filter_wiphy = state.filter_wiphy;
4006 
4007 		/*
4008 		 * if filtering, set cb->args[2] to +1 since 0 is the default
4009 		 * value needed to determine that parsing is necessary.
4010 		 */
4011 		if (filter_wiphy >= 0)
4012 			cb->args[2] = filter_wiphy + 1;
4013 		else
4014 			cb->args[2] = -1;
4015 	} else if (cb->args[2] > 0) {
4016 		filter_wiphy = cb->args[2] - 1;
4017 	}
4018 
4019 	list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
4020 		if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
4021 			continue;
4022 		if (wp_idx < wp_start) {
4023 			wp_idx++;
4024 			continue;
4025 		}
4026 
4027 		if (filter_wiphy >= 0 && filter_wiphy != rdev->wiphy_idx)
4028 			continue;
4029 
4030 		if_idx = 0;
4031 
4032 		list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
4033 			if (if_idx < if_start) {
4034 				if_idx++;
4035 				continue;
4036 			}
4037 			if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
4038 					       cb->nlh->nlmsg_seq, NLM_F_MULTI,
4039 					       rdev, wdev,
4040 					       NL80211_CMD_NEW_INTERFACE) < 0) {
4041 				goto out;
4042 			}
4043 			if_idx++;
4044 		}
4045 
4046 		if_start = 0;
4047 		wp_idx++;
4048 	}
4049  out:
4050 	cb->args[0] = wp_idx;
4051 	cb->args[1] = if_idx;
4052 
4053 	ret = skb->len;
4054  out_unlock:
4055 	rtnl_unlock();
4056 
4057 	return ret;
4058 }
4059 
nl80211_get_interface(struct sk_buff * skb,struct genl_info * info)4060 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
4061 {
4062 	struct sk_buff *msg;
4063 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4064 	struct wireless_dev *wdev = info->user_ptr[1];
4065 
4066 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4067 	if (!msg)
4068 		return -ENOMEM;
4069 
4070 	if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
4071 			       rdev, wdev, NL80211_CMD_NEW_INTERFACE) < 0) {
4072 		nlmsg_free(msg);
4073 		return -ENOBUFS;
4074 	}
4075 
4076 	return genlmsg_reply(msg, info);
4077 }
4078 
4079 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
4080 	[NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
4081 	[NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
4082 	[NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
4083 	[NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
4084 	[NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
4085 	[NL80211_MNTR_FLAG_ACTIVE] = { .type = NLA_FLAG },
4086 };
4087 
parse_monitor_flags(struct nlattr * nla,u32 * mntrflags)4088 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
4089 {
4090 	struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
4091 	int flag;
4092 
4093 	*mntrflags = 0;
4094 
4095 	if (!nla)
4096 		return -EINVAL;
4097 
4098 	if (nla_parse_nested_deprecated(flags, NL80211_MNTR_FLAG_MAX, nla, mntr_flags_policy, NULL))
4099 		return -EINVAL;
4100 
4101 	for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
4102 		if (flags[flag])
4103 			*mntrflags |= (1<<flag);
4104 
4105 	/* cooked monitor mode is incompatible with other modes */
4106 	if (*mntrflags & MONITOR_FLAG_COOK_FRAMES &&
4107 	    *mntrflags != MONITOR_FLAG_COOK_FRAMES)
4108 		return -EOPNOTSUPP;
4109 
4110 	*mntrflags |= MONITOR_FLAG_CHANGED;
4111 
4112 	return 0;
4113 }
4114 
nl80211_parse_mon_options(struct cfg80211_registered_device * rdev,enum nl80211_iftype type,struct genl_info * info,struct vif_params * params)4115 static int nl80211_parse_mon_options(struct cfg80211_registered_device *rdev,
4116 				     enum nl80211_iftype type,
4117 				     struct genl_info *info,
4118 				     struct vif_params *params)
4119 {
4120 	bool change = false;
4121 	int err;
4122 
4123 	if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4124 		if (type != NL80211_IFTYPE_MONITOR)
4125 			return -EINVAL;
4126 
4127 		err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
4128 					  &params->flags);
4129 		if (err)
4130 			return err;
4131 
4132 		change = true;
4133 	}
4134 
4135 	if (params->flags & MONITOR_FLAG_ACTIVE &&
4136 	    !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
4137 		return -EOPNOTSUPP;
4138 
4139 	if (info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]) {
4140 		const u8 *mumimo_groups;
4141 		u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER;
4142 
4143 		if (type != NL80211_IFTYPE_MONITOR)
4144 			return -EINVAL;
4145 
4146 		if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag))
4147 			return -EOPNOTSUPP;
4148 
4149 		mumimo_groups =
4150 			nla_data(info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]);
4151 
4152 		/* bits 0 and 63 are reserved and must be zero */
4153 		if ((mumimo_groups[0] & BIT(0)) ||
4154 		    (mumimo_groups[VHT_MUMIMO_GROUPS_DATA_LEN - 1] & BIT(7)))
4155 			return -EINVAL;
4156 
4157 		params->vht_mumimo_groups = mumimo_groups;
4158 		change = true;
4159 	}
4160 
4161 	if (info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR]) {
4162 		u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER;
4163 
4164 		if (type != NL80211_IFTYPE_MONITOR)
4165 			return -EINVAL;
4166 
4167 		if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag))
4168 			return -EOPNOTSUPP;
4169 
4170 		params->vht_mumimo_follow_addr =
4171 			nla_data(info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR]);
4172 		change = true;
4173 	}
4174 
4175 	return change ? 1 : 0;
4176 }
4177 
nl80211_valid_4addr(struct cfg80211_registered_device * rdev,struct net_device * netdev,u8 use_4addr,enum nl80211_iftype iftype)4178 static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
4179 			       struct net_device *netdev, u8 use_4addr,
4180 			       enum nl80211_iftype iftype)
4181 {
4182 	if (!use_4addr) {
4183 		if (netdev && netif_is_bridge_port(netdev))
4184 			return -EBUSY;
4185 		return 0;
4186 	}
4187 
4188 	switch (iftype) {
4189 	case NL80211_IFTYPE_AP_VLAN:
4190 		if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
4191 			return 0;
4192 		break;
4193 	case NL80211_IFTYPE_STATION:
4194 		if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
4195 			return 0;
4196 		break;
4197 	default:
4198 		break;
4199 	}
4200 
4201 	return -EOPNOTSUPP;
4202 }
4203 
nl80211_set_interface(struct sk_buff * skb,struct genl_info * info)4204 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
4205 {
4206 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4207 	struct vif_params params;
4208 	int err;
4209 	enum nl80211_iftype otype, ntype;
4210 	struct net_device *dev = info->user_ptr[1];
4211 	bool change = false;
4212 
4213 	memset(&params, 0, sizeof(params));
4214 
4215 	otype = ntype = dev->ieee80211_ptr->iftype;
4216 
4217 	if (info->attrs[NL80211_ATTR_IFTYPE]) {
4218 		ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
4219 		if (otype != ntype)
4220 			change = true;
4221 	}
4222 
4223 	if (info->attrs[NL80211_ATTR_MESH_ID]) {
4224 		struct wireless_dev *wdev = dev->ieee80211_ptr;
4225 
4226 		if (ntype != NL80211_IFTYPE_MESH_POINT)
4227 			return -EINVAL;
4228 		if (otype != NL80211_IFTYPE_MESH_POINT)
4229 			return -EINVAL;
4230 		if (netif_running(dev))
4231 			return -EBUSY;
4232 
4233 		wdev_lock(wdev);
4234 		BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
4235 			     IEEE80211_MAX_MESH_ID_LEN);
4236 		wdev->u.mesh.id_up_len =
4237 			nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
4238 		memcpy(wdev->u.mesh.id,
4239 		       nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
4240 		       wdev->u.mesh.id_up_len);
4241 		wdev_unlock(wdev);
4242 	}
4243 
4244 	if (info->attrs[NL80211_ATTR_4ADDR]) {
4245 		params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
4246 		change = true;
4247 		err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
4248 		if (err)
4249 			return err;
4250 	} else {
4251 		params.use_4addr = -1;
4252 	}
4253 
4254 	err = nl80211_parse_mon_options(rdev, ntype, info, &params);
4255 	if (err < 0)
4256 		return err;
4257 	if (err > 0)
4258 		change = true;
4259 
4260 	if (change)
4261 		err = cfg80211_change_iface(rdev, dev, ntype, &params);
4262 	else
4263 		err = 0;
4264 
4265 	if (!err && params.use_4addr != -1)
4266 		dev->ieee80211_ptr->use_4addr = params.use_4addr;
4267 
4268 	if (change && !err) {
4269 		struct wireless_dev *wdev = dev->ieee80211_ptr;
4270 
4271 		nl80211_notify_iface(rdev, wdev, NL80211_CMD_SET_INTERFACE);
4272 	}
4273 
4274 	return err;
4275 }
4276 
_nl80211_new_interface(struct sk_buff * skb,struct genl_info * info)4277 static int _nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
4278 {
4279 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4280 	struct vif_params params;
4281 	struct wireless_dev *wdev;
4282 	struct sk_buff *msg;
4283 	int err;
4284 	enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
4285 
4286 	memset(&params, 0, sizeof(params));
4287 
4288 	if (!info->attrs[NL80211_ATTR_IFNAME])
4289 		return -EINVAL;
4290 
4291 	if (info->attrs[NL80211_ATTR_IFTYPE])
4292 		type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
4293 
4294 	if (!rdev->ops->add_virtual_intf)
4295 		return -EOPNOTSUPP;
4296 
4297 	if ((type == NL80211_IFTYPE_P2P_DEVICE || type == NL80211_IFTYPE_NAN ||
4298 	     rdev->wiphy.features & NL80211_FEATURE_MAC_ON_CREATE) &&
4299 	    info->attrs[NL80211_ATTR_MAC]) {
4300 		nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC],
4301 			   ETH_ALEN);
4302 		if (!is_valid_ether_addr(params.macaddr))
4303 			return -EADDRNOTAVAIL;
4304 	}
4305 
4306 	if (info->attrs[NL80211_ATTR_4ADDR]) {
4307 		params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
4308 		err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
4309 		if (err)
4310 			return err;
4311 	}
4312 
4313 	if (!cfg80211_iftype_allowed(&rdev->wiphy, type, params.use_4addr, 0))
4314 		return -EOPNOTSUPP;
4315 
4316 	err = nl80211_parse_mon_options(rdev, type, info, &params);
4317 	if (err < 0)
4318 		return err;
4319 
4320 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4321 	if (!msg)
4322 		return -ENOMEM;
4323 
4324 	wdev = rdev_add_virtual_intf(rdev,
4325 				nla_data(info->attrs[NL80211_ATTR_IFNAME]),
4326 				NET_NAME_USER, type, &params);
4327 	if (WARN_ON(!wdev)) {
4328 		nlmsg_free(msg);
4329 		return -EPROTO;
4330 	} else if (IS_ERR(wdev)) {
4331 		nlmsg_free(msg);
4332 		return PTR_ERR(wdev);
4333 	}
4334 
4335 	if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
4336 		wdev->owner_nlportid = info->snd_portid;
4337 
4338 	switch (type) {
4339 	case NL80211_IFTYPE_MESH_POINT:
4340 		if (!info->attrs[NL80211_ATTR_MESH_ID])
4341 			break;
4342 		wdev_lock(wdev);
4343 		BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
4344 			     IEEE80211_MAX_MESH_ID_LEN);
4345 		wdev->u.mesh.id_up_len =
4346 			nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
4347 		memcpy(wdev->u.mesh.id,
4348 		       nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
4349 		       wdev->u.mesh.id_up_len);
4350 		wdev_unlock(wdev);
4351 		break;
4352 	case NL80211_IFTYPE_NAN:
4353 	case NL80211_IFTYPE_P2P_DEVICE:
4354 		/*
4355 		 * P2P Device and NAN do not have a netdev, so don't go
4356 		 * through the netdev notifier and must be added here
4357 		 */
4358 		cfg80211_init_wdev(wdev);
4359 		cfg80211_register_wdev(rdev, wdev);
4360 		break;
4361 	default:
4362 		break;
4363 	}
4364 
4365 	if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
4366 			       rdev, wdev, NL80211_CMD_NEW_INTERFACE) < 0) {
4367 		nlmsg_free(msg);
4368 		return -ENOBUFS;
4369 	}
4370 
4371 	return genlmsg_reply(msg, info);
4372 }
4373 
nl80211_new_interface(struct sk_buff * skb,struct genl_info * info)4374 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
4375 {
4376 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4377 	int ret;
4378 
4379 	/* to avoid failing a new interface creation due to pending removal */
4380 	cfg80211_destroy_ifaces(rdev);
4381 
4382 	wiphy_lock(&rdev->wiphy);
4383 	ret = _nl80211_new_interface(skb, info);
4384 	wiphy_unlock(&rdev->wiphy);
4385 
4386 	return ret;
4387 }
4388 
nl80211_del_interface(struct sk_buff * skb,struct genl_info * info)4389 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
4390 {
4391 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4392 	struct wireless_dev *wdev = info->user_ptr[1];
4393 
4394 	if (!rdev->ops->del_virtual_intf)
4395 		return -EOPNOTSUPP;
4396 
4397 	/*
4398 	 * We hold RTNL, so this is safe, without RTNL opencount cannot
4399 	 * reach 0, and thus the rdev cannot be deleted.
4400 	 *
4401 	 * We need to do it for the dev_close(), since that will call
4402 	 * the netdev notifiers, and we need to acquire the mutex there
4403 	 * but don't know if we get there from here or from some other
4404 	 * place (e.g. "ip link set ... down").
4405 	 */
4406 	mutex_unlock(&rdev->wiphy.mtx);
4407 
4408 	/*
4409 	 * If we remove a wireless device without a netdev then clear
4410 	 * user_ptr[1] so that nl80211_post_doit won't dereference it
4411 	 * to check if it needs to do dev_put(). Otherwise it crashes
4412 	 * since the wdev has been freed, unlike with a netdev where
4413 	 * we need the dev_put() for the netdev to really be freed.
4414 	 */
4415 	if (!wdev->netdev)
4416 		info->user_ptr[1] = NULL;
4417 	else
4418 		dev_close(wdev->netdev);
4419 
4420 	mutex_lock(&rdev->wiphy.mtx);
4421 
4422 	return cfg80211_remove_virtual_intf(rdev, wdev);
4423 }
4424 
nl80211_set_noack_map(struct sk_buff * skb,struct genl_info * info)4425 static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
4426 {
4427 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4428 	struct net_device *dev = info->user_ptr[1];
4429 	u16 noack_map;
4430 
4431 	if (!info->attrs[NL80211_ATTR_NOACK_MAP])
4432 		return -EINVAL;
4433 
4434 	if (!rdev->ops->set_noack_map)
4435 		return -EOPNOTSUPP;
4436 
4437 	noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
4438 
4439 	return rdev_set_noack_map(rdev, dev, noack_map);
4440 }
4441 
nl80211_validate_key_link_id(struct genl_info * info,struct wireless_dev * wdev,int link_id,bool pairwise)4442 static int nl80211_validate_key_link_id(struct genl_info *info,
4443 					struct wireless_dev *wdev,
4444 					int link_id, bool pairwise)
4445 {
4446 	if (pairwise) {
4447 		if (link_id != -1) {
4448 			GENL_SET_ERR_MSG(info,
4449 					 "link ID not allowed for pairwise key");
4450 			return -EINVAL;
4451 		}
4452 
4453 		return 0;
4454 	}
4455 
4456 	if (wdev->valid_links) {
4457 		if (link_id == -1) {
4458 			GENL_SET_ERR_MSG(info,
4459 					 "link ID must for MLO group key");
4460 			return -EINVAL;
4461 		}
4462 		if (!(wdev->valid_links & BIT(link_id))) {
4463 			GENL_SET_ERR_MSG(info, "invalid link ID for MLO group key");
4464 			return -EINVAL;
4465 		}
4466 	} else if (link_id != -1) {
4467 		GENL_SET_ERR_MSG(info, "link ID not allowed for non-MLO group key");
4468 		return -EINVAL;
4469 	}
4470 
4471 	return 0;
4472 }
4473 
4474 struct get_key_cookie {
4475 	struct sk_buff *msg;
4476 	int error;
4477 	int idx;
4478 };
4479 
get_key_callback(void * c,struct key_params * params)4480 static void get_key_callback(void *c, struct key_params *params)
4481 {
4482 	struct nlattr *key;
4483 	struct get_key_cookie *cookie = c;
4484 
4485 	if ((params->seq &&
4486 	     nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
4487 		     params->seq_len, params->seq)) ||
4488 	    (params->cipher &&
4489 	     nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
4490 			 params->cipher)))
4491 		goto nla_put_failure;
4492 
4493 	key = nla_nest_start_noflag(cookie->msg, NL80211_ATTR_KEY);
4494 	if (!key)
4495 		goto nla_put_failure;
4496 
4497 	if ((params->seq &&
4498 	     nla_put(cookie->msg, NL80211_KEY_SEQ,
4499 		     params->seq_len, params->seq)) ||
4500 	    (params->cipher &&
4501 	     nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
4502 			 params->cipher)))
4503 		goto nla_put_failure;
4504 
4505 	if (nla_put_u8(cookie->msg, NL80211_KEY_IDX, cookie->idx))
4506 		goto nla_put_failure;
4507 
4508 	nla_nest_end(cookie->msg, key);
4509 
4510 	return;
4511  nla_put_failure:
4512 	cookie->error = 1;
4513 }
4514 
nl80211_get_key(struct sk_buff * skb,struct genl_info * info)4515 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
4516 {
4517 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4518 	int err;
4519 	struct net_device *dev = info->user_ptr[1];
4520 	u8 key_idx = 0;
4521 	const u8 *mac_addr = NULL;
4522 	bool pairwise;
4523 	struct get_key_cookie cookie = {
4524 		.error = 0,
4525 	};
4526 	void *hdr;
4527 	struct sk_buff *msg;
4528 	bool bigtk_support = false;
4529 	int link_id = nl80211_link_id_or_invalid(info->attrs);
4530 	struct wireless_dev *wdev = dev->ieee80211_ptr;
4531 
4532 	if (wiphy_ext_feature_isset(&rdev->wiphy,
4533 				    NL80211_EXT_FEATURE_BEACON_PROTECTION))
4534 		bigtk_support = true;
4535 
4536 	if ((wdev->iftype == NL80211_IFTYPE_STATION ||
4537 	     wdev->iftype == NL80211_IFTYPE_P2P_CLIENT) &&
4538 	    wiphy_ext_feature_isset(&rdev->wiphy,
4539 				    NL80211_EXT_FEATURE_BEACON_PROTECTION_CLIENT))
4540 		bigtk_support = true;
4541 
4542 	if (info->attrs[NL80211_ATTR_KEY_IDX]) {
4543 		key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
4544 
4545 		if (key_idx >= 6 && key_idx <= 7 && !bigtk_support) {
4546 			GENL_SET_ERR_MSG(info, "BIGTK not supported");
4547 			return -EINVAL;
4548 		}
4549 	}
4550 
4551 	if (info->attrs[NL80211_ATTR_MAC])
4552 		mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4553 
4554 	pairwise = !!mac_addr;
4555 	if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
4556 		u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
4557 
4558 		if (kt != NL80211_KEYTYPE_GROUP &&
4559 		    kt != NL80211_KEYTYPE_PAIRWISE)
4560 			return -EINVAL;
4561 		pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
4562 	}
4563 
4564 	if (!rdev->ops->get_key)
4565 		return -EOPNOTSUPP;
4566 
4567 	if (!pairwise && mac_addr && !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
4568 		return -ENOENT;
4569 
4570 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4571 	if (!msg)
4572 		return -ENOMEM;
4573 
4574 	hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
4575 			     NL80211_CMD_NEW_KEY);
4576 	if (!hdr)
4577 		goto nla_put_failure;
4578 
4579 	cookie.msg = msg;
4580 	cookie.idx = key_idx;
4581 
4582 	if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
4583 	    nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
4584 		goto nla_put_failure;
4585 	if (mac_addr &&
4586 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
4587 		goto nla_put_failure;
4588 
4589 	err = nl80211_validate_key_link_id(info, wdev, link_id, pairwise);
4590 	if (err)
4591 		goto free_msg;
4592 
4593 	err = rdev_get_key(rdev, dev, link_id, key_idx, pairwise, mac_addr,
4594 			   &cookie, get_key_callback);
4595 
4596 	if (err)
4597 		goto free_msg;
4598 
4599 	if (cookie.error)
4600 		goto nla_put_failure;
4601 
4602 	genlmsg_end(msg, hdr);
4603 	return genlmsg_reply(msg, info);
4604 
4605  nla_put_failure:
4606 	err = -ENOBUFS;
4607  free_msg:
4608 	nlmsg_free(msg);
4609 	return err;
4610 }
4611 
nl80211_set_key(struct sk_buff * skb,struct genl_info * info)4612 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
4613 {
4614 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4615 	struct key_parse key;
4616 	int err;
4617 	struct net_device *dev = info->user_ptr[1];
4618 	int link_id = nl80211_link_id_or_invalid(info->attrs);
4619 	struct wireless_dev *wdev = dev->ieee80211_ptr;
4620 
4621 	err = nl80211_parse_key(info, &key);
4622 	if (err)
4623 		return err;
4624 
4625 	if (key.idx < 0)
4626 		return -EINVAL;
4627 
4628 	/* Only support setting default key and
4629 	 * Extended Key ID action NL80211_KEY_SET_TX.
4630 	 */
4631 	if (!key.def && !key.defmgmt && !key.defbeacon &&
4632 	    !(key.p.mode == NL80211_KEY_SET_TX))
4633 		return -EINVAL;
4634 
4635 	wdev_lock(wdev);
4636 
4637 	if (key.def) {
4638 		if (!rdev->ops->set_default_key) {
4639 			err = -EOPNOTSUPP;
4640 			goto out;
4641 		}
4642 
4643 		err = nl80211_key_allowed(wdev);
4644 		if (err)
4645 			goto out;
4646 
4647 		err = nl80211_validate_key_link_id(info, wdev, link_id, false);
4648 		if (err)
4649 			goto out;
4650 
4651 		err = rdev_set_default_key(rdev, dev, link_id, key.idx,
4652 					   key.def_uni, key.def_multi);
4653 
4654 		if (err)
4655 			goto out;
4656 
4657 #ifdef CONFIG_CFG80211_WEXT
4658 		wdev->wext.default_key = key.idx;
4659 #endif
4660 	} else if (key.defmgmt) {
4661 		if (key.def_uni || !key.def_multi) {
4662 			err = -EINVAL;
4663 			goto out;
4664 		}
4665 
4666 		if (!rdev->ops->set_default_mgmt_key) {
4667 			err = -EOPNOTSUPP;
4668 			goto out;
4669 		}
4670 
4671 		err = nl80211_key_allowed(wdev);
4672 		if (err)
4673 			goto out;
4674 
4675 		err = nl80211_validate_key_link_id(info, wdev, link_id, false);
4676 		if (err)
4677 			goto out;
4678 
4679 		err = rdev_set_default_mgmt_key(rdev, dev, link_id, key.idx);
4680 		if (err)
4681 			goto out;
4682 
4683 #ifdef CONFIG_CFG80211_WEXT
4684 		wdev->wext.default_mgmt_key = key.idx;
4685 #endif
4686 	} else if (key.defbeacon) {
4687 		if (key.def_uni || !key.def_multi) {
4688 			err = -EINVAL;
4689 			goto out;
4690 		}
4691 
4692 		if (!rdev->ops->set_default_beacon_key) {
4693 			err = -EOPNOTSUPP;
4694 			goto out;
4695 		}
4696 
4697 		err = nl80211_key_allowed(wdev);
4698 		if (err)
4699 			goto out;
4700 
4701 		err = nl80211_validate_key_link_id(info, wdev, link_id, false);
4702 		if (err)
4703 			goto out;
4704 
4705 		err = rdev_set_default_beacon_key(rdev, dev, link_id, key.idx);
4706 		if (err)
4707 			goto out;
4708 	} else if (key.p.mode == NL80211_KEY_SET_TX &&
4709 		   wiphy_ext_feature_isset(&rdev->wiphy,
4710 					   NL80211_EXT_FEATURE_EXT_KEY_ID)) {
4711 		u8 *mac_addr = NULL;
4712 
4713 		if (info->attrs[NL80211_ATTR_MAC])
4714 			mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4715 
4716 		if (!mac_addr || key.idx < 0 || key.idx > 1) {
4717 			err = -EINVAL;
4718 			goto out;
4719 		}
4720 
4721 		err = nl80211_validate_key_link_id(info, wdev, link_id, true);
4722 		if (err)
4723 			goto out;
4724 
4725 		err = rdev_add_key(rdev, dev, link_id, key.idx,
4726 				   NL80211_KEYTYPE_PAIRWISE,
4727 				   mac_addr, &key.p);
4728 	} else {
4729 		err = -EINVAL;
4730 	}
4731  out:
4732 	wdev_unlock(wdev);
4733 
4734 	return err;
4735 }
4736 
nl80211_new_key(struct sk_buff * skb,struct genl_info * info)4737 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
4738 {
4739 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4740 	int err;
4741 	struct net_device *dev = info->user_ptr[1];
4742 	struct key_parse key;
4743 	const u8 *mac_addr = NULL;
4744 	int link_id = nl80211_link_id_or_invalid(info->attrs);
4745 	struct wireless_dev *wdev = dev->ieee80211_ptr;
4746 
4747 	err = nl80211_parse_key(info, &key);
4748 	if (err)
4749 		return err;
4750 
4751 	if (!key.p.key) {
4752 		GENL_SET_ERR_MSG(info, "no key");
4753 		return -EINVAL;
4754 	}
4755 
4756 	if (info->attrs[NL80211_ATTR_MAC])
4757 		mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4758 
4759 	if (key.type == -1) {
4760 		if (mac_addr)
4761 			key.type = NL80211_KEYTYPE_PAIRWISE;
4762 		else
4763 			key.type = NL80211_KEYTYPE_GROUP;
4764 	}
4765 
4766 	/* for now */
4767 	if (key.type != NL80211_KEYTYPE_PAIRWISE &&
4768 	    key.type != NL80211_KEYTYPE_GROUP) {
4769 		GENL_SET_ERR_MSG(info, "key type not pairwise or group");
4770 		return -EINVAL;
4771 	}
4772 
4773 	if (key.type == NL80211_KEYTYPE_GROUP &&
4774 	    info->attrs[NL80211_ATTR_VLAN_ID])
4775 		key.p.vlan_id = nla_get_u16(info->attrs[NL80211_ATTR_VLAN_ID]);
4776 
4777 	if (!rdev->ops->add_key)
4778 		return -EOPNOTSUPP;
4779 
4780 	if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
4781 					   key.type == NL80211_KEYTYPE_PAIRWISE,
4782 					   mac_addr)) {
4783 		GENL_SET_ERR_MSG(info, "key setting validation failed");
4784 		return -EINVAL;
4785 	}
4786 
4787 	wdev_lock(wdev);
4788 	err = nl80211_key_allowed(wdev);
4789 	if (err)
4790 		GENL_SET_ERR_MSG(info, "key not allowed");
4791 
4792 	if (!err)
4793 		err = nl80211_validate_key_link_id(info, wdev, link_id,
4794 				key.type == NL80211_KEYTYPE_PAIRWISE);
4795 
4796 	if (!err) {
4797 		err = rdev_add_key(rdev, dev, link_id, key.idx,
4798 				   key.type == NL80211_KEYTYPE_PAIRWISE,
4799 				    mac_addr, &key.p);
4800 		if (err)
4801 			GENL_SET_ERR_MSG(info, "key addition failed");
4802 	}
4803 	wdev_unlock(wdev);
4804 
4805 	return err;
4806 }
4807 
nl80211_del_key(struct sk_buff * skb,struct genl_info * info)4808 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
4809 {
4810 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4811 	int err;
4812 	struct net_device *dev = info->user_ptr[1];
4813 	u8 *mac_addr = NULL;
4814 	struct key_parse key;
4815 	int link_id = nl80211_link_id_or_invalid(info->attrs);
4816 	struct wireless_dev *wdev = dev->ieee80211_ptr;
4817 
4818 	err = nl80211_parse_key(info, &key);
4819 	if (err)
4820 		return err;
4821 
4822 	if (info->attrs[NL80211_ATTR_MAC])
4823 		mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4824 
4825 	if (key.type == -1) {
4826 		if (mac_addr)
4827 			key.type = NL80211_KEYTYPE_PAIRWISE;
4828 		else
4829 			key.type = NL80211_KEYTYPE_GROUP;
4830 	}
4831 
4832 	/* for now */
4833 	if (key.type != NL80211_KEYTYPE_PAIRWISE &&
4834 	    key.type != NL80211_KEYTYPE_GROUP)
4835 		return -EINVAL;
4836 
4837 	if (!cfg80211_valid_key_idx(rdev, key.idx,
4838 				    key.type == NL80211_KEYTYPE_PAIRWISE))
4839 		return -EINVAL;
4840 
4841 	if (!rdev->ops->del_key)
4842 		return -EOPNOTSUPP;
4843 
4844 	wdev_lock(wdev);
4845 	err = nl80211_key_allowed(wdev);
4846 
4847 	if (key.type == NL80211_KEYTYPE_GROUP && mac_addr &&
4848 	    !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
4849 		err = -ENOENT;
4850 
4851 	if (!err)
4852 		err = nl80211_validate_key_link_id(info, wdev, link_id,
4853 				key.type == NL80211_KEYTYPE_PAIRWISE);
4854 
4855 	if (!err)
4856 		err = rdev_del_key(rdev, dev, link_id, key.idx,
4857 				   key.type == NL80211_KEYTYPE_PAIRWISE,
4858 				   mac_addr);
4859 
4860 #ifdef CONFIG_CFG80211_WEXT
4861 	if (!err) {
4862 		if (key.idx == wdev->wext.default_key)
4863 			wdev->wext.default_key = -1;
4864 		else if (key.idx == wdev->wext.default_mgmt_key)
4865 			wdev->wext.default_mgmt_key = -1;
4866 	}
4867 #endif
4868 	wdev_unlock(wdev);
4869 
4870 	return err;
4871 }
4872 
4873 /* This function returns an error or the number of nested attributes */
validate_acl_mac_addrs(struct nlattr * nl_attr)4874 static int validate_acl_mac_addrs(struct nlattr *nl_attr)
4875 {
4876 	struct nlattr *attr;
4877 	int n_entries = 0, tmp;
4878 
4879 	nla_for_each_nested(attr, nl_attr, tmp) {
4880 		if (nla_len(attr) != ETH_ALEN)
4881 			return -EINVAL;
4882 
4883 		n_entries++;
4884 	}
4885 
4886 	return n_entries;
4887 }
4888 
4889 /*
4890  * This function parses ACL information and allocates memory for ACL data.
4891  * On successful return, the calling function is responsible to free the
4892  * ACL buffer returned by this function.
4893  */
parse_acl_data(struct wiphy * wiphy,struct genl_info * info)4894 static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy,
4895 						struct genl_info *info)
4896 {
4897 	enum nl80211_acl_policy acl_policy;
4898 	struct nlattr *attr;
4899 	struct cfg80211_acl_data *acl;
4900 	int i = 0, n_entries, tmp;
4901 
4902 	if (!wiphy->max_acl_mac_addrs)
4903 		return ERR_PTR(-EOPNOTSUPP);
4904 
4905 	if (!info->attrs[NL80211_ATTR_ACL_POLICY])
4906 		return ERR_PTR(-EINVAL);
4907 
4908 	acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]);
4909 	if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED &&
4910 	    acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED)
4911 		return ERR_PTR(-EINVAL);
4912 
4913 	if (!info->attrs[NL80211_ATTR_MAC_ADDRS])
4914 		return ERR_PTR(-EINVAL);
4915 
4916 	n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]);
4917 	if (n_entries < 0)
4918 		return ERR_PTR(n_entries);
4919 
4920 	if (n_entries > wiphy->max_acl_mac_addrs)
4921 		return ERR_PTR(-ENOTSUPP);
4922 
4923 	acl = kzalloc(struct_size(acl, mac_addrs, n_entries), GFP_KERNEL);
4924 	if (!acl)
4925 		return ERR_PTR(-ENOMEM);
4926 	acl->n_acl_entries = n_entries;
4927 
4928 	nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) {
4929 		memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN);
4930 		i++;
4931 	}
4932 	acl->acl_policy = acl_policy;
4933 
4934 	return acl;
4935 }
4936 
nl80211_set_mac_acl(struct sk_buff * skb,struct genl_info * info)4937 static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info)
4938 {
4939 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4940 	struct net_device *dev = info->user_ptr[1];
4941 	struct cfg80211_acl_data *acl;
4942 	int err;
4943 
4944 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4945 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4946 		return -EOPNOTSUPP;
4947 
4948 	if (!dev->ieee80211_ptr->links[0].ap.beacon_interval)
4949 		return -EINVAL;
4950 
4951 	acl = parse_acl_data(&rdev->wiphy, info);
4952 	if (IS_ERR(acl))
4953 		return PTR_ERR(acl);
4954 
4955 	err = rdev_set_mac_acl(rdev, dev, acl);
4956 
4957 	kfree(acl);
4958 
4959 	return err;
4960 }
4961 
rateset_to_mask(struct ieee80211_supported_band * sband,u8 * rates,u8 rates_len)4962 static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4963 			   u8 *rates, u8 rates_len)
4964 {
4965 	u8 i;
4966 	u32 mask = 0;
4967 
4968 	for (i = 0; i < rates_len; i++) {
4969 		int rate = (rates[i] & 0x7f) * 5;
4970 		int ridx;
4971 
4972 		for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4973 			struct ieee80211_rate *srate =
4974 				&sband->bitrates[ridx];
4975 			if (rate == srate->bitrate) {
4976 				mask |= 1 << ridx;
4977 				break;
4978 			}
4979 		}
4980 		if (ridx == sband->n_bitrates)
4981 			return 0; /* rate not found */
4982 	}
4983 
4984 	return mask;
4985 }
4986 
ht_rateset_to_mask(struct ieee80211_supported_band * sband,u8 * rates,u8 rates_len,u8 mcs[IEEE80211_HT_MCS_MASK_LEN])4987 static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
4988 			       u8 *rates, u8 rates_len,
4989 			       u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
4990 {
4991 	u8 i;
4992 
4993 	memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
4994 
4995 	for (i = 0; i < rates_len; i++) {
4996 		int ridx, rbit;
4997 
4998 		ridx = rates[i] / 8;
4999 		rbit = BIT(rates[i] % 8);
5000 
5001 		/* check validity */
5002 		if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
5003 			return false;
5004 
5005 		/* check availability */
5006 		ridx = array_index_nospec(ridx, IEEE80211_HT_MCS_MASK_LEN);
5007 		if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
5008 			mcs[ridx] |= rbit;
5009 		else
5010 			return false;
5011 	}
5012 
5013 	return true;
5014 }
5015 
vht_mcs_map_to_mcs_mask(u8 vht_mcs_map)5016 static u16 vht_mcs_map_to_mcs_mask(u8 vht_mcs_map)
5017 {
5018 	u16 mcs_mask = 0;
5019 
5020 	switch (vht_mcs_map) {
5021 	case IEEE80211_VHT_MCS_NOT_SUPPORTED:
5022 		break;
5023 	case IEEE80211_VHT_MCS_SUPPORT_0_7:
5024 		mcs_mask = 0x00FF;
5025 		break;
5026 	case IEEE80211_VHT_MCS_SUPPORT_0_8:
5027 		mcs_mask = 0x01FF;
5028 		break;
5029 	case IEEE80211_VHT_MCS_SUPPORT_0_9:
5030 		mcs_mask = 0x03FF;
5031 		break;
5032 	default:
5033 		break;
5034 	}
5035 
5036 	return mcs_mask;
5037 }
5038 
vht_build_mcs_mask(u16 vht_mcs_map,u16 vht_mcs_mask[NL80211_VHT_NSS_MAX])5039 static void vht_build_mcs_mask(u16 vht_mcs_map,
5040 			       u16 vht_mcs_mask[NL80211_VHT_NSS_MAX])
5041 {
5042 	u8 nss;
5043 
5044 	for (nss = 0; nss < NL80211_VHT_NSS_MAX; nss++) {
5045 		vht_mcs_mask[nss] = vht_mcs_map_to_mcs_mask(vht_mcs_map & 0x03);
5046 		vht_mcs_map >>= 2;
5047 	}
5048 }
5049 
vht_set_mcs_mask(struct ieee80211_supported_band * sband,struct nl80211_txrate_vht * txrate,u16 mcs[NL80211_VHT_NSS_MAX])5050 static bool vht_set_mcs_mask(struct ieee80211_supported_band *sband,
5051 			     struct nl80211_txrate_vht *txrate,
5052 			     u16 mcs[NL80211_VHT_NSS_MAX])
5053 {
5054 	u16 tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
5055 	u16 tx_mcs_mask[NL80211_VHT_NSS_MAX] = {};
5056 	u8 i;
5057 
5058 	if (!sband->vht_cap.vht_supported)
5059 		return false;
5060 
5061 	memset(mcs, 0, sizeof(u16) * NL80211_VHT_NSS_MAX);
5062 
5063 	/* Build vht_mcs_mask from VHT capabilities */
5064 	vht_build_mcs_mask(tx_mcs_map, tx_mcs_mask);
5065 
5066 	for (i = 0; i < NL80211_VHT_NSS_MAX; i++) {
5067 		if ((tx_mcs_mask[i] & txrate->mcs[i]) == txrate->mcs[i])
5068 			mcs[i] = txrate->mcs[i];
5069 		else
5070 			return false;
5071 	}
5072 
5073 	return true;
5074 }
5075 
he_mcs_map_to_mcs_mask(u8 he_mcs_map)5076 static u16 he_mcs_map_to_mcs_mask(u8 he_mcs_map)
5077 {
5078 	switch (he_mcs_map) {
5079 	case IEEE80211_HE_MCS_NOT_SUPPORTED:
5080 		return 0;
5081 	case IEEE80211_HE_MCS_SUPPORT_0_7:
5082 		return 0x00FF;
5083 	case IEEE80211_HE_MCS_SUPPORT_0_9:
5084 		return 0x03FF;
5085 	case IEEE80211_HE_MCS_SUPPORT_0_11:
5086 		return 0xFFF;
5087 	default:
5088 		break;
5089 	}
5090 	return 0;
5091 }
5092 
he_build_mcs_mask(u16 he_mcs_map,u16 he_mcs_mask[NL80211_HE_NSS_MAX])5093 static void he_build_mcs_mask(u16 he_mcs_map,
5094 			      u16 he_mcs_mask[NL80211_HE_NSS_MAX])
5095 {
5096 	u8 nss;
5097 
5098 	for (nss = 0; nss < NL80211_HE_NSS_MAX; nss++) {
5099 		he_mcs_mask[nss] = he_mcs_map_to_mcs_mask(he_mcs_map & 0x03);
5100 		he_mcs_map >>= 2;
5101 	}
5102 }
5103 
he_get_txmcsmap(struct genl_info * info,unsigned int link_id,const struct ieee80211_sta_he_cap * he_cap)5104 static u16 he_get_txmcsmap(struct genl_info *info, unsigned int link_id,
5105 			   const struct ieee80211_sta_he_cap *he_cap)
5106 {
5107 	struct net_device *dev = info->user_ptr[1];
5108 	struct wireless_dev *wdev = dev->ieee80211_ptr;
5109 	struct cfg80211_chan_def *chandef;
5110 	__le16 tx_mcs;
5111 
5112 	chandef = wdev_chandef(wdev, link_id);
5113 	if (!chandef) {
5114 		/*
5115 		 * This is probably broken, but we never maintained
5116 		 * a chandef in these cases, so it always was.
5117 		 */
5118 		return le16_to_cpu(he_cap->he_mcs_nss_supp.tx_mcs_80);
5119 	}
5120 
5121 	switch (chandef->width) {
5122 	case NL80211_CHAN_WIDTH_80P80:
5123 		tx_mcs = he_cap->he_mcs_nss_supp.tx_mcs_80p80;
5124 		break;
5125 	case NL80211_CHAN_WIDTH_160:
5126 		tx_mcs = he_cap->he_mcs_nss_supp.tx_mcs_160;
5127 		break;
5128 	default:
5129 		tx_mcs = he_cap->he_mcs_nss_supp.tx_mcs_80;
5130 		break;
5131 	}
5132 
5133 	return le16_to_cpu(tx_mcs);
5134 }
5135 
he_set_mcs_mask(struct genl_info * info,struct wireless_dev * wdev,struct ieee80211_supported_band * sband,struct nl80211_txrate_he * txrate,u16 mcs[NL80211_HE_NSS_MAX],unsigned int link_id)5136 static bool he_set_mcs_mask(struct genl_info *info,
5137 			    struct wireless_dev *wdev,
5138 			    struct ieee80211_supported_band *sband,
5139 			    struct nl80211_txrate_he *txrate,
5140 			    u16 mcs[NL80211_HE_NSS_MAX],
5141 			    unsigned int link_id)
5142 {
5143 	const struct ieee80211_sta_he_cap *he_cap;
5144 	u16 tx_mcs_mask[NL80211_HE_NSS_MAX] = {};
5145 	u16 tx_mcs_map = 0;
5146 	u8 i;
5147 
5148 	he_cap = ieee80211_get_he_iftype_cap(sband, wdev->iftype);
5149 	if (!he_cap)
5150 		return false;
5151 
5152 	memset(mcs, 0, sizeof(u16) * NL80211_HE_NSS_MAX);
5153 
5154 	tx_mcs_map = he_get_txmcsmap(info, link_id, he_cap);
5155 
5156 	/* Build he_mcs_mask from HE capabilities */
5157 	he_build_mcs_mask(tx_mcs_map, tx_mcs_mask);
5158 
5159 	for (i = 0; i < NL80211_HE_NSS_MAX; i++) {
5160 		if ((tx_mcs_mask[i] & txrate->mcs[i]) == txrate->mcs[i])
5161 			mcs[i] = txrate->mcs[i];
5162 		else
5163 			return false;
5164 	}
5165 
5166 	return true;
5167 }
5168 
nl80211_parse_tx_bitrate_mask(struct genl_info * info,struct nlattr * attrs[],enum nl80211_attrs attr,struct cfg80211_bitrate_mask * mask,struct net_device * dev,bool default_all_enabled,unsigned int link_id)5169 static int nl80211_parse_tx_bitrate_mask(struct genl_info *info,
5170 					 struct nlattr *attrs[],
5171 					 enum nl80211_attrs attr,
5172 					 struct cfg80211_bitrate_mask *mask,
5173 					 struct net_device *dev,
5174 					 bool default_all_enabled,
5175 					 unsigned int link_id)
5176 {
5177 	struct nlattr *tb[NL80211_TXRATE_MAX + 1];
5178 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5179 	struct wireless_dev *wdev = dev->ieee80211_ptr;
5180 	int rem, i;
5181 	struct nlattr *tx_rates;
5182 	struct ieee80211_supported_band *sband;
5183 	u16 vht_tx_mcs_map, he_tx_mcs_map;
5184 
5185 	memset(mask, 0, sizeof(*mask));
5186 	/* Default to all rates enabled */
5187 	for (i = 0; i < NUM_NL80211_BANDS; i++) {
5188 		const struct ieee80211_sta_he_cap *he_cap;
5189 
5190 		if (!default_all_enabled)
5191 			break;
5192 
5193 		sband = rdev->wiphy.bands[i];
5194 
5195 		if (!sband)
5196 			continue;
5197 
5198 		mask->control[i].legacy = (1 << sband->n_bitrates) - 1;
5199 		memcpy(mask->control[i].ht_mcs,
5200 		       sband->ht_cap.mcs.rx_mask,
5201 		       sizeof(mask->control[i].ht_mcs));
5202 
5203 		if (sband->vht_cap.vht_supported) {
5204 			vht_tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
5205 			vht_build_mcs_mask(vht_tx_mcs_map, mask->control[i].vht_mcs);
5206 		}
5207 
5208 		he_cap = ieee80211_get_he_iftype_cap(sband, wdev->iftype);
5209 		if (!he_cap)
5210 			continue;
5211 
5212 		he_tx_mcs_map = he_get_txmcsmap(info, link_id, he_cap);
5213 		he_build_mcs_mask(he_tx_mcs_map, mask->control[i].he_mcs);
5214 
5215 		mask->control[i].he_gi = 0xFF;
5216 		mask->control[i].he_ltf = 0xFF;
5217 	}
5218 
5219 	/* if no rates are given set it back to the defaults */
5220 	if (!attrs[attr])
5221 		goto out;
5222 
5223 	/* The nested attribute uses enum nl80211_band as the index. This maps
5224 	 * directly to the enum nl80211_band values used in cfg80211.
5225 	 */
5226 	BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
5227 	nla_for_each_nested(tx_rates, attrs[attr], rem) {
5228 		enum nl80211_band band = nla_type(tx_rates);
5229 		int err;
5230 
5231 		if (band < 0 || band >= NUM_NL80211_BANDS)
5232 			return -EINVAL;
5233 		sband = rdev->wiphy.bands[band];
5234 		if (sband == NULL)
5235 			return -EINVAL;
5236 		err = nla_parse_nested_deprecated(tb, NL80211_TXRATE_MAX,
5237 						  tx_rates,
5238 						  nl80211_txattr_policy,
5239 						  info->extack);
5240 		if (err)
5241 			return err;
5242 		if (tb[NL80211_TXRATE_LEGACY]) {
5243 			mask->control[band].legacy = rateset_to_mask(
5244 				sband,
5245 				nla_data(tb[NL80211_TXRATE_LEGACY]),
5246 				nla_len(tb[NL80211_TXRATE_LEGACY]));
5247 			if ((mask->control[band].legacy == 0) &&
5248 			    nla_len(tb[NL80211_TXRATE_LEGACY]))
5249 				return -EINVAL;
5250 		}
5251 		if (tb[NL80211_TXRATE_HT]) {
5252 			if (!ht_rateset_to_mask(
5253 					sband,
5254 					nla_data(tb[NL80211_TXRATE_HT]),
5255 					nla_len(tb[NL80211_TXRATE_HT]),
5256 					mask->control[band].ht_mcs))
5257 				return -EINVAL;
5258 		}
5259 
5260 		if (tb[NL80211_TXRATE_VHT]) {
5261 			if (!vht_set_mcs_mask(
5262 					sband,
5263 					nla_data(tb[NL80211_TXRATE_VHT]),
5264 					mask->control[band].vht_mcs))
5265 				return -EINVAL;
5266 		}
5267 
5268 		if (tb[NL80211_TXRATE_GI]) {
5269 			mask->control[band].gi =
5270 				nla_get_u8(tb[NL80211_TXRATE_GI]);
5271 			if (mask->control[band].gi > NL80211_TXRATE_FORCE_LGI)
5272 				return -EINVAL;
5273 		}
5274 		if (tb[NL80211_TXRATE_HE] &&
5275 		    !he_set_mcs_mask(info, wdev, sband,
5276 				     nla_data(tb[NL80211_TXRATE_HE]),
5277 				     mask->control[band].he_mcs,
5278 				     link_id))
5279 			return -EINVAL;
5280 
5281 		if (tb[NL80211_TXRATE_HE_GI])
5282 			mask->control[band].he_gi =
5283 				nla_get_u8(tb[NL80211_TXRATE_HE_GI]);
5284 		if (tb[NL80211_TXRATE_HE_LTF])
5285 			mask->control[band].he_ltf =
5286 				nla_get_u8(tb[NL80211_TXRATE_HE_LTF]);
5287 
5288 		if (mask->control[band].legacy == 0) {
5289 			/* don't allow empty legacy rates if HT, VHT or HE
5290 			 * are not even supported.
5291 			 */
5292 			if (!(rdev->wiphy.bands[band]->ht_cap.ht_supported ||
5293 			      rdev->wiphy.bands[band]->vht_cap.vht_supported ||
5294 			      ieee80211_get_he_iftype_cap(sband, wdev->iftype)))
5295 				return -EINVAL;
5296 
5297 			for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
5298 				if (mask->control[band].ht_mcs[i])
5299 					goto out;
5300 
5301 			for (i = 0; i < NL80211_VHT_NSS_MAX; i++)
5302 				if (mask->control[band].vht_mcs[i])
5303 					goto out;
5304 
5305 			for (i = 0; i < NL80211_HE_NSS_MAX; i++)
5306 				if (mask->control[band].he_mcs[i])
5307 					goto out;
5308 
5309 			/* legacy and mcs rates may not be both empty */
5310 			return -EINVAL;
5311 		}
5312 	}
5313 
5314 out:
5315 	return 0;
5316 }
5317 
validate_beacon_tx_rate(struct cfg80211_registered_device * rdev,enum nl80211_band band,struct cfg80211_bitrate_mask * beacon_rate)5318 static int validate_beacon_tx_rate(struct cfg80211_registered_device *rdev,
5319 				   enum nl80211_band band,
5320 				   struct cfg80211_bitrate_mask *beacon_rate)
5321 {
5322 	u32 count_ht, count_vht, count_he, i;
5323 	u32 rate = beacon_rate->control[band].legacy;
5324 
5325 	/* Allow only one rate */
5326 	if (hweight32(rate) > 1)
5327 		return -EINVAL;
5328 
5329 	count_ht = 0;
5330 	for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++) {
5331 		if (hweight8(beacon_rate->control[band].ht_mcs[i]) > 1) {
5332 			return -EINVAL;
5333 		} else if (beacon_rate->control[band].ht_mcs[i]) {
5334 			count_ht++;
5335 			if (count_ht > 1)
5336 				return -EINVAL;
5337 		}
5338 		if (count_ht && rate)
5339 			return -EINVAL;
5340 	}
5341 
5342 	count_vht = 0;
5343 	for (i = 0; i < NL80211_VHT_NSS_MAX; i++) {
5344 		if (hweight16(beacon_rate->control[band].vht_mcs[i]) > 1) {
5345 			return -EINVAL;
5346 		} else if (beacon_rate->control[band].vht_mcs[i]) {
5347 			count_vht++;
5348 			if (count_vht > 1)
5349 				return -EINVAL;
5350 		}
5351 		if (count_vht && rate)
5352 			return -EINVAL;
5353 	}
5354 
5355 	count_he = 0;
5356 	for (i = 0; i < NL80211_HE_NSS_MAX; i++) {
5357 		if (hweight16(beacon_rate->control[band].he_mcs[i]) > 1) {
5358 			return -EINVAL;
5359 		} else if (beacon_rate->control[band].he_mcs[i]) {
5360 			count_he++;
5361 			if (count_he > 1)
5362 				return -EINVAL;
5363 		}
5364 		if (count_he && rate)
5365 			return -EINVAL;
5366 	}
5367 
5368 	if ((count_ht && count_vht && count_he) ||
5369 	    (!rate && !count_ht && !count_vht && !count_he))
5370 		return -EINVAL;
5371 
5372 	if (rate &&
5373 	    !wiphy_ext_feature_isset(&rdev->wiphy,
5374 				     NL80211_EXT_FEATURE_BEACON_RATE_LEGACY))
5375 		return -EINVAL;
5376 	if (count_ht &&
5377 	    !wiphy_ext_feature_isset(&rdev->wiphy,
5378 				     NL80211_EXT_FEATURE_BEACON_RATE_HT))
5379 		return -EINVAL;
5380 	if (count_vht &&
5381 	    !wiphy_ext_feature_isset(&rdev->wiphy,
5382 				     NL80211_EXT_FEATURE_BEACON_RATE_VHT))
5383 		return -EINVAL;
5384 	if (count_he &&
5385 	    !wiphy_ext_feature_isset(&rdev->wiphy,
5386 				     NL80211_EXT_FEATURE_BEACON_RATE_HE))
5387 		return -EINVAL;
5388 
5389 	return 0;
5390 }
5391 
nl80211_parse_mbssid_config(struct wiphy * wiphy,struct net_device * dev,struct nlattr * attrs,struct cfg80211_mbssid_config * config,u8 num_elems)5392 static int nl80211_parse_mbssid_config(struct wiphy *wiphy,
5393 				       struct net_device *dev,
5394 				       struct nlattr *attrs,
5395 				       struct cfg80211_mbssid_config *config,
5396 				       u8 num_elems)
5397 {
5398 	struct nlattr *tb[NL80211_MBSSID_CONFIG_ATTR_MAX + 1];
5399 
5400 	if (!wiphy->mbssid_max_interfaces)
5401 		return -EOPNOTSUPP;
5402 
5403 	if (nla_parse_nested(tb, NL80211_MBSSID_CONFIG_ATTR_MAX, attrs, NULL,
5404 			     NULL) ||
5405 	    !tb[NL80211_MBSSID_CONFIG_ATTR_INDEX])
5406 		return -EINVAL;
5407 
5408 	config->ema = nla_get_flag(tb[NL80211_MBSSID_CONFIG_ATTR_EMA]);
5409 	if (config->ema) {
5410 		if (!wiphy->ema_max_profile_periodicity)
5411 			return -EOPNOTSUPP;
5412 
5413 		if (num_elems > wiphy->ema_max_profile_periodicity)
5414 			return -EINVAL;
5415 	}
5416 
5417 	config->index = nla_get_u8(tb[NL80211_MBSSID_CONFIG_ATTR_INDEX]);
5418 	if (config->index >= wiphy->mbssid_max_interfaces ||
5419 	    (!config->index && !num_elems))
5420 		return -EINVAL;
5421 
5422 	if (tb[NL80211_MBSSID_CONFIG_ATTR_TX_IFINDEX]) {
5423 		u32 tx_ifindex =
5424 			nla_get_u32(tb[NL80211_MBSSID_CONFIG_ATTR_TX_IFINDEX]);
5425 
5426 		if ((!config->index && tx_ifindex != dev->ifindex) ||
5427 		    (config->index && tx_ifindex == dev->ifindex))
5428 			return -EINVAL;
5429 
5430 		if (tx_ifindex != dev->ifindex) {
5431 			struct net_device *tx_netdev =
5432 				dev_get_by_index(wiphy_net(wiphy), tx_ifindex);
5433 
5434 			if (!tx_netdev || !tx_netdev->ieee80211_ptr ||
5435 			    tx_netdev->ieee80211_ptr->wiphy != wiphy ||
5436 			    tx_netdev->ieee80211_ptr->iftype !=
5437 							NL80211_IFTYPE_AP) {
5438 				dev_put(tx_netdev);
5439 				return -EINVAL;
5440 			}
5441 
5442 			config->tx_wdev = tx_netdev->ieee80211_ptr;
5443 		} else {
5444 			config->tx_wdev = dev->ieee80211_ptr;
5445 		}
5446 	} else if (!config->index) {
5447 		config->tx_wdev = dev->ieee80211_ptr;
5448 	} else {
5449 		return -EINVAL;
5450 	}
5451 
5452 	return 0;
5453 }
5454 
5455 static struct cfg80211_mbssid_elems *
nl80211_parse_mbssid_elems(struct wiphy * wiphy,struct nlattr * attrs)5456 nl80211_parse_mbssid_elems(struct wiphy *wiphy, struct nlattr *attrs)
5457 {
5458 	struct nlattr *nl_elems;
5459 	struct cfg80211_mbssid_elems *elems;
5460 	int rem_elems;
5461 	u8 i = 0, num_elems = 0;
5462 
5463 	if (!wiphy->mbssid_max_interfaces)
5464 		return ERR_PTR(-EINVAL);
5465 
5466 	nla_for_each_nested(nl_elems, attrs, rem_elems) {
5467 		if (num_elems >= 255)
5468 			return ERR_PTR(-EINVAL);
5469 		num_elems++;
5470 	}
5471 
5472 	elems = kzalloc(struct_size(elems, elem, num_elems), GFP_KERNEL);
5473 	if (!elems)
5474 		return ERR_PTR(-ENOMEM);
5475 	elems->cnt = num_elems;
5476 
5477 	nla_for_each_nested(nl_elems, attrs, rem_elems) {
5478 		elems->elem[i].data = nla_data(nl_elems);
5479 		elems->elem[i].len = nla_len(nl_elems);
5480 		i++;
5481 	}
5482 	return elems;
5483 }
5484 
5485 static struct cfg80211_rnr_elems *
nl80211_parse_rnr_elems(struct wiphy * wiphy,struct nlattr * attrs,struct netlink_ext_ack * extack)5486 nl80211_parse_rnr_elems(struct wiphy *wiphy, struct nlattr *attrs,
5487 			struct netlink_ext_ack *extack)
5488 {
5489 	struct nlattr *nl_elems;
5490 	struct cfg80211_rnr_elems *elems;
5491 	int rem_elems;
5492 	u8 i = 0, num_elems = 0;
5493 
5494 	nla_for_each_nested(nl_elems, attrs, rem_elems) {
5495 		int ret;
5496 
5497 		ret = validate_ie_attr(nl_elems, extack);
5498 		if (ret)
5499 			return ERR_PTR(ret);
5500 
5501 		num_elems++;
5502 	}
5503 
5504 	elems = kzalloc(struct_size(elems, elem, num_elems), GFP_KERNEL);
5505 	if (!elems)
5506 		return ERR_PTR(-ENOMEM);
5507 	elems->cnt = num_elems;
5508 
5509 	nla_for_each_nested(nl_elems, attrs, rem_elems) {
5510 		elems->elem[i].data = nla_data(nl_elems);
5511 		elems->elem[i].len = nla_len(nl_elems);
5512 		i++;
5513 	}
5514 	return elems;
5515 }
5516 
nl80211_parse_he_bss_color(struct nlattr * attrs,struct cfg80211_he_bss_color * he_bss_color)5517 static int nl80211_parse_he_bss_color(struct nlattr *attrs,
5518 				      struct cfg80211_he_bss_color *he_bss_color)
5519 {
5520 	struct nlattr *tb[NL80211_HE_BSS_COLOR_ATTR_MAX + 1];
5521 	int err;
5522 
5523 	err = nla_parse_nested(tb, NL80211_HE_BSS_COLOR_ATTR_MAX, attrs,
5524 			       he_bss_color_policy, NULL);
5525 	if (err)
5526 		return err;
5527 
5528 	if (!tb[NL80211_HE_BSS_COLOR_ATTR_COLOR])
5529 		return -EINVAL;
5530 
5531 	he_bss_color->color =
5532 		nla_get_u8(tb[NL80211_HE_BSS_COLOR_ATTR_COLOR]);
5533 	he_bss_color->enabled =
5534 		!nla_get_flag(tb[NL80211_HE_BSS_COLOR_ATTR_DISABLED]);
5535 	he_bss_color->partial =
5536 		nla_get_flag(tb[NL80211_HE_BSS_COLOR_ATTR_PARTIAL]);
5537 
5538 	return 0;
5539 }
5540 
nl80211_parse_beacon(struct cfg80211_registered_device * rdev,struct nlattr * attrs[],struct cfg80211_beacon_data * bcn,struct netlink_ext_ack * extack)5541 static int nl80211_parse_beacon(struct cfg80211_registered_device *rdev,
5542 				struct nlattr *attrs[],
5543 				struct cfg80211_beacon_data *bcn,
5544 				struct netlink_ext_ack *extack)
5545 {
5546 	bool haveinfo = false;
5547 	int err;
5548 
5549 	memset(bcn, 0, sizeof(*bcn));
5550 
5551 	bcn->link_id = nl80211_link_id(attrs);
5552 
5553 	if (attrs[NL80211_ATTR_BEACON_HEAD]) {
5554 		bcn->head = nla_data(attrs[NL80211_ATTR_BEACON_HEAD]);
5555 		bcn->head_len = nla_len(attrs[NL80211_ATTR_BEACON_HEAD]);
5556 		if (!bcn->head_len)
5557 			return -EINVAL;
5558 		haveinfo = true;
5559 	}
5560 
5561 	if (attrs[NL80211_ATTR_BEACON_TAIL]) {
5562 		bcn->tail = nla_data(attrs[NL80211_ATTR_BEACON_TAIL]);
5563 		bcn->tail_len = nla_len(attrs[NL80211_ATTR_BEACON_TAIL]);
5564 		haveinfo = true;
5565 	}
5566 
5567 	if (!haveinfo)
5568 		return -EINVAL;
5569 
5570 	if (attrs[NL80211_ATTR_IE]) {
5571 		bcn->beacon_ies = nla_data(attrs[NL80211_ATTR_IE]);
5572 		bcn->beacon_ies_len = nla_len(attrs[NL80211_ATTR_IE]);
5573 	}
5574 
5575 	if (attrs[NL80211_ATTR_IE_PROBE_RESP]) {
5576 		bcn->proberesp_ies =
5577 			nla_data(attrs[NL80211_ATTR_IE_PROBE_RESP]);
5578 		bcn->proberesp_ies_len =
5579 			nla_len(attrs[NL80211_ATTR_IE_PROBE_RESP]);
5580 	}
5581 
5582 	if (attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
5583 		bcn->assocresp_ies =
5584 			nla_data(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
5585 		bcn->assocresp_ies_len =
5586 			nla_len(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
5587 	}
5588 
5589 	if (attrs[NL80211_ATTR_PROBE_RESP]) {
5590 		bcn->probe_resp = nla_data(attrs[NL80211_ATTR_PROBE_RESP]);
5591 		bcn->probe_resp_len = nla_len(attrs[NL80211_ATTR_PROBE_RESP]);
5592 	}
5593 
5594 	if (attrs[NL80211_ATTR_FTM_RESPONDER]) {
5595 		struct nlattr *tb[NL80211_FTM_RESP_ATTR_MAX + 1];
5596 
5597 		err = nla_parse_nested_deprecated(tb,
5598 						  NL80211_FTM_RESP_ATTR_MAX,
5599 						  attrs[NL80211_ATTR_FTM_RESPONDER],
5600 						  NULL, NULL);
5601 		if (err)
5602 			return err;
5603 
5604 		if (tb[NL80211_FTM_RESP_ATTR_ENABLED] &&
5605 		    wiphy_ext_feature_isset(&rdev->wiphy,
5606 					    NL80211_EXT_FEATURE_ENABLE_FTM_RESPONDER))
5607 			bcn->ftm_responder = 1;
5608 		else
5609 			return -EOPNOTSUPP;
5610 
5611 		if (tb[NL80211_FTM_RESP_ATTR_LCI]) {
5612 			bcn->lci = nla_data(tb[NL80211_FTM_RESP_ATTR_LCI]);
5613 			bcn->lci_len = nla_len(tb[NL80211_FTM_RESP_ATTR_LCI]);
5614 		}
5615 
5616 		if (tb[NL80211_FTM_RESP_ATTR_CIVICLOC]) {
5617 			bcn->civicloc = nla_data(tb[NL80211_FTM_RESP_ATTR_CIVICLOC]);
5618 			bcn->civicloc_len = nla_len(tb[NL80211_FTM_RESP_ATTR_CIVICLOC]);
5619 		}
5620 	} else {
5621 		bcn->ftm_responder = -1;
5622 	}
5623 
5624 	if (attrs[NL80211_ATTR_HE_BSS_COLOR]) {
5625 		err = nl80211_parse_he_bss_color(attrs[NL80211_ATTR_HE_BSS_COLOR],
5626 						 &bcn->he_bss_color);
5627 		if (err)
5628 			return err;
5629 		bcn->he_bss_color_valid = true;
5630 	}
5631 
5632 	if (attrs[NL80211_ATTR_MBSSID_ELEMS]) {
5633 		struct cfg80211_mbssid_elems *mbssid =
5634 			nl80211_parse_mbssid_elems(&rdev->wiphy,
5635 						   attrs[NL80211_ATTR_MBSSID_ELEMS]);
5636 
5637 		if (IS_ERR(mbssid))
5638 			return PTR_ERR(mbssid);
5639 
5640 		bcn->mbssid_ies = mbssid;
5641 
5642 		if (bcn->mbssid_ies && attrs[NL80211_ATTR_EMA_RNR_ELEMS]) {
5643 			struct cfg80211_rnr_elems *rnr =
5644 				nl80211_parse_rnr_elems(&rdev->wiphy,
5645 							attrs[NL80211_ATTR_EMA_RNR_ELEMS],
5646 							extack);
5647 
5648 			if (IS_ERR(rnr))
5649 				return PTR_ERR(rnr);
5650 
5651 			if (rnr && rnr->cnt < bcn->mbssid_ies->cnt)
5652 				return -EINVAL;
5653 
5654 			bcn->rnr_ies = rnr;
5655 		}
5656 	}
5657 
5658 	return 0;
5659 }
5660 
nl80211_parse_he_obss_pd(struct nlattr * attrs,struct ieee80211_he_obss_pd * he_obss_pd)5661 static int nl80211_parse_he_obss_pd(struct nlattr *attrs,
5662 				    struct ieee80211_he_obss_pd *he_obss_pd)
5663 {
5664 	struct nlattr *tb[NL80211_HE_OBSS_PD_ATTR_MAX + 1];
5665 	int err;
5666 
5667 	err = nla_parse_nested(tb, NL80211_HE_OBSS_PD_ATTR_MAX, attrs,
5668 			       he_obss_pd_policy, NULL);
5669 	if (err)
5670 		return err;
5671 
5672 	if (!tb[NL80211_HE_OBSS_PD_ATTR_SR_CTRL])
5673 		return -EINVAL;
5674 
5675 	he_obss_pd->sr_ctrl = nla_get_u8(tb[NL80211_HE_OBSS_PD_ATTR_SR_CTRL]);
5676 
5677 	if (tb[NL80211_HE_OBSS_PD_ATTR_MIN_OFFSET])
5678 		he_obss_pd->min_offset =
5679 			nla_get_u8(tb[NL80211_HE_OBSS_PD_ATTR_MIN_OFFSET]);
5680 	if (tb[NL80211_HE_OBSS_PD_ATTR_MAX_OFFSET])
5681 		he_obss_pd->max_offset =
5682 			nla_get_u8(tb[NL80211_HE_OBSS_PD_ATTR_MAX_OFFSET]);
5683 	if (tb[NL80211_HE_OBSS_PD_ATTR_NON_SRG_MAX_OFFSET])
5684 		he_obss_pd->non_srg_max_offset =
5685 			nla_get_u8(tb[NL80211_HE_OBSS_PD_ATTR_NON_SRG_MAX_OFFSET]);
5686 
5687 	if (he_obss_pd->min_offset > he_obss_pd->max_offset)
5688 		return -EINVAL;
5689 
5690 	if (tb[NL80211_HE_OBSS_PD_ATTR_BSS_COLOR_BITMAP])
5691 		memcpy(he_obss_pd->bss_color_bitmap,
5692 		       nla_data(tb[NL80211_HE_OBSS_PD_ATTR_BSS_COLOR_BITMAP]),
5693 		       sizeof(he_obss_pd->bss_color_bitmap));
5694 
5695 	if (tb[NL80211_HE_OBSS_PD_ATTR_PARTIAL_BSSID_BITMAP])
5696 		memcpy(he_obss_pd->partial_bssid_bitmap,
5697 		       nla_data(tb[NL80211_HE_OBSS_PD_ATTR_PARTIAL_BSSID_BITMAP]),
5698 		       sizeof(he_obss_pd->partial_bssid_bitmap));
5699 
5700 	he_obss_pd->enable = true;
5701 
5702 	return 0;
5703 }
5704 
nl80211_parse_fils_discovery(struct cfg80211_registered_device * rdev,struct nlattr * attrs,struct cfg80211_ap_settings * params)5705 static int nl80211_parse_fils_discovery(struct cfg80211_registered_device *rdev,
5706 					struct nlattr *attrs,
5707 					struct cfg80211_ap_settings *params)
5708 {
5709 	struct nlattr *tb[NL80211_FILS_DISCOVERY_ATTR_MAX + 1];
5710 	int ret;
5711 	struct cfg80211_fils_discovery *fd = &params->fils_discovery;
5712 
5713 	if (!wiphy_ext_feature_isset(&rdev->wiphy,
5714 				     NL80211_EXT_FEATURE_FILS_DISCOVERY))
5715 		return -EINVAL;
5716 
5717 	ret = nla_parse_nested(tb, NL80211_FILS_DISCOVERY_ATTR_MAX, attrs,
5718 			       NULL, NULL);
5719 	if (ret)
5720 		return ret;
5721 
5722 	if (!tb[NL80211_FILS_DISCOVERY_ATTR_INT_MIN] ||
5723 	    !tb[NL80211_FILS_DISCOVERY_ATTR_INT_MAX] ||
5724 	    !tb[NL80211_FILS_DISCOVERY_ATTR_TMPL])
5725 		return -EINVAL;
5726 
5727 	fd->tmpl_len = nla_len(tb[NL80211_FILS_DISCOVERY_ATTR_TMPL]);
5728 	fd->tmpl = nla_data(tb[NL80211_FILS_DISCOVERY_ATTR_TMPL]);
5729 	fd->min_interval = nla_get_u32(tb[NL80211_FILS_DISCOVERY_ATTR_INT_MIN]);
5730 	fd->max_interval = nla_get_u32(tb[NL80211_FILS_DISCOVERY_ATTR_INT_MAX]);
5731 
5732 	return 0;
5733 }
5734 
5735 static int
nl80211_parse_unsol_bcast_probe_resp(struct cfg80211_registered_device * rdev,struct nlattr * attrs,struct cfg80211_ap_settings * params)5736 nl80211_parse_unsol_bcast_probe_resp(struct cfg80211_registered_device *rdev,
5737 				     struct nlattr *attrs,
5738 				     struct cfg80211_ap_settings *params)
5739 {
5740 	struct nlattr *tb[NL80211_UNSOL_BCAST_PROBE_RESP_ATTR_MAX + 1];
5741 	int ret;
5742 	struct cfg80211_unsol_bcast_probe_resp *presp =
5743 					&params->unsol_bcast_probe_resp;
5744 
5745 	if (!wiphy_ext_feature_isset(&rdev->wiphy,
5746 				     NL80211_EXT_FEATURE_UNSOL_BCAST_PROBE_RESP))
5747 		return -EINVAL;
5748 
5749 	ret = nla_parse_nested(tb, NL80211_UNSOL_BCAST_PROBE_RESP_ATTR_MAX,
5750 			       attrs, NULL, NULL);
5751 	if (ret)
5752 		return ret;
5753 
5754 	if (!tb[NL80211_UNSOL_BCAST_PROBE_RESP_ATTR_INT] ||
5755 	    !tb[NL80211_UNSOL_BCAST_PROBE_RESP_ATTR_TMPL])
5756 		return -EINVAL;
5757 
5758 	presp->tmpl = nla_data(tb[NL80211_UNSOL_BCAST_PROBE_RESP_ATTR_TMPL]);
5759 	presp->tmpl_len = nla_len(tb[NL80211_UNSOL_BCAST_PROBE_RESP_ATTR_TMPL]);
5760 	presp->interval = nla_get_u32(tb[NL80211_UNSOL_BCAST_PROBE_RESP_ATTR_INT]);
5761 	return 0;
5762 }
5763 
nl80211_check_ap_rate_selectors(struct cfg80211_ap_settings * params,const struct element * rates)5764 static void nl80211_check_ap_rate_selectors(struct cfg80211_ap_settings *params,
5765 					    const struct element *rates)
5766 {
5767 	int i;
5768 
5769 	if (!rates)
5770 		return;
5771 
5772 	for (i = 0; i < rates->datalen; i++) {
5773 		if (rates->data[i] == BSS_MEMBERSHIP_SELECTOR_HT_PHY)
5774 			params->ht_required = true;
5775 		if (rates->data[i] == BSS_MEMBERSHIP_SELECTOR_VHT_PHY)
5776 			params->vht_required = true;
5777 		if (rates->data[i] == BSS_MEMBERSHIP_SELECTOR_HE_PHY)
5778 			params->he_required = true;
5779 		if (rates->data[i] == BSS_MEMBERSHIP_SELECTOR_SAE_H2E)
5780 			params->sae_h2e_required = true;
5781 	}
5782 }
5783 
5784 /*
5785  * Since the nl80211 API didn't include, from the beginning, attributes about
5786  * HT/VHT requirements/capabilities, we parse them out of the IEs for the
5787  * benefit of drivers that rebuild IEs in the firmware.
5788  */
nl80211_calculate_ap_params(struct cfg80211_ap_settings * params)5789 static int nl80211_calculate_ap_params(struct cfg80211_ap_settings *params)
5790 {
5791 	const struct cfg80211_beacon_data *bcn = &params->beacon;
5792 	size_t ies_len = bcn->tail_len;
5793 	const u8 *ies = bcn->tail;
5794 	const struct element *rates;
5795 	const struct element *cap;
5796 
5797 	rates = cfg80211_find_elem(WLAN_EID_SUPP_RATES, ies, ies_len);
5798 	nl80211_check_ap_rate_selectors(params, rates);
5799 
5800 	rates = cfg80211_find_elem(WLAN_EID_EXT_SUPP_RATES, ies, ies_len);
5801 	nl80211_check_ap_rate_selectors(params, rates);
5802 
5803 	cap = cfg80211_find_elem(WLAN_EID_HT_CAPABILITY, ies, ies_len);
5804 	if (cap && cap->datalen >= sizeof(*params->ht_cap))
5805 		params->ht_cap = (void *)cap->data;
5806 	cap = cfg80211_find_elem(WLAN_EID_VHT_CAPABILITY, ies, ies_len);
5807 	if (cap && cap->datalen >= sizeof(*params->vht_cap))
5808 		params->vht_cap = (void *)cap->data;
5809 	cap = cfg80211_find_ext_elem(WLAN_EID_EXT_HE_CAPABILITY, ies, ies_len);
5810 	if (cap && cap->datalen >= sizeof(*params->he_cap) + 1)
5811 		params->he_cap = (void *)(cap->data + 1);
5812 	cap = cfg80211_find_ext_elem(WLAN_EID_EXT_HE_OPERATION, ies, ies_len);
5813 	if (cap && cap->datalen >= sizeof(*params->he_oper) + 1)
5814 		params->he_oper = (void *)(cap->data + 1);
5815 	cap = cfg80211_find_ext_elem(WLAN_EID_EXT_EHT_CAPABILITY, ies, ies_len);
5816 	if (cap) {
5817 		if (!cap->datalen)
5818 			return -EINVAL;
5819 		params->eht_cap = (void *)(cap->data + 1);
5820 		if (!ieee80211_eht_capa_size_ok((const u8 *)params->he_cap,
5821 						(const u8 *)params->eht_cap,
5822 						cap->datalen - 1, true))
5823 			return -EINVAL;
5824 	}
5825 	cap = cfg80211_find_ext_elem(WLAN_EID_EXT_EHT_OPERATION, ies, ies_len);
5826 	if (cap) {
5827 		if (!cap->datalen)
5828 			return -EINVAL;
5829 		params->eht_oper = (void *)(cap->data + 1);
5830 		if (!ieee80211_eht_oper_size_ok((const u8 *)params->eht_oper,
5831 						cap->datalen - 1))
5832 			return -EINVAL;
5833 	}
5834 	return 0;
5835 }
5836 
nl80211_get_ap_channel(struct cfg80211_registered_device * rdev,struct cfg80211_ap_settings * params)5837 static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
5838 				   struct cfg80211_ap_settings *params)
5839 {
5840 	struct wireless_dev *wdev;
5841 
5842 	list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
5843 		if (wdev->iftype != NL80211_IFTYPE_AP &&
5844 		    wdev->iftype != NL80211_IFTYPE_P2P_GO)
5845 			continue;
5846 
5847 		if (!wdev->u.ap.preset_chandef.chan)
5848 			continue;
5849 
5850 		params->chandef = wdev->u.ap.preset_chandef;
5851 		return true;
5852 	}
5853 
5854 	return false;
5855 }
5856 
nl80211_valid_auth_type(struct cfg80211_registered_device * rdev,enum nl80211_auth_type auth_type,enum nl80211_commands cmd)5857 static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
5858 				    enum nl80211_auth_type auth_type,
5859 				    enum nl80211_commands cmd)
5860 {
5861 	if (auth_type > NL80211_AUTHTYPE_MAX)
5862 		return false;
5863 
5864 	switch (cmd) {
5865 	case NL80211_CMD_AUTHENTICATE:
5866 		if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
5867 		    auth_type == NL80211_AUTHTYPE_SAE)
5868 			return false;
5869 		if (!wiphy_ext_feature_isset(&rdev->wiphy,
5870 					     NL80211_EXT_FEATURE_FILS_STA) &&
5871 		    (auth_type == NL80211_AUTHTYPE_FILS_SK ||
5872 		     auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
5873 		     auth_type == NL80211_AUTHTYPE_FILS_PK))
5874 			return false;
5875 		return true;
5876 	case NL80211_CMD_CONNECT:
5877 		if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
5878 		    !wiphy_ext_feature_isset(&rdev->wiphy,
5879 					     NL80211_EXT_FEATURE_SAE_OFFLOAD) &&
5880 		    auth_type == NL80211_AUTHTYPE_SAE)
5881 			return false;
5882 
5883 		/* FILS with SK PFS or PK not supported yet */
5884 		if (auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
5885 		    auth_type == NL80211_AUTHTYPE_FILS_PK)
5886 			return false;
5887 		if (!wiphy_ext_feature_isset(
5888 			    &rdev->wiphy,
5889 			    NL80211_EXT_FEATURE_FILS_SK_OFFLOAD) &&
5890 		    auth_type == NL80211_AUTHTYPE_FILS_SK)
5891 			return false;
5892 		return true;
5893 	case NL80211_CMD_START_AP:
5894 		if (!wiphy_ext_feature_isset(&rdev->wiphy,
5895 					     NL80211_EXT_FEATURE_SAE_OFFLOAD_AP) &&
5896 		    auth_type == NL80211_AUTHTYPE_SAE)
5897 			return false;
5898 		/* FILS not supported yet */
5899 		if (auth_type == NL80211_AUTHTYPE_FILS_SK ||
5900 		    auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
5901 		    auth_type == NL80211_AUTHTYPE_FILS_PK)
5902 			return false;
5903 		return true;
5904 	default:
5905 		return false;
5906 	}
5907 }
5908 
nl80211_send_ap_started(struct wireless_dev * wdev,unsigned int link_id)5909 static void nl80211_send_ap_started(struct wireless_dev *wdev,
5910 				    unsigned int link_id)
5911 {
5912 	struct wiphy *wiphy = wdev->wiphy;
5913 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
5914 	struct sk_buff *msg;
5915 	void *hdr;
5916 
5917 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5918 	if (!msg)
5919 		return;
5920 
5921 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_START_AP);
5922 	if (!hdr)
5923 		goto out;
5924 
5925 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
5926 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex) ||
5927 	    nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
5928 			      NL80211_ATTR_PAD) ||
5929 	    (wdev->u.ap.ssid_len &&
5930 	     nla_put(msg, NL80211_ATTR_SSID, wdev->u.ap.ssid_len,
5931 		     wdev->u.ap.ssid)) ||
5932 	    (wdev->valid_links &&
5933 	     nla_put_u8(msg, NL80211_ATTR_MLO_LINK_ID, link_id)))
5934 		goto out;
5935 
5936 	genlmsg_end(msg, hdr);
5937 
5938 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(wiphy), msg, 0,
5939 				NL80211_MCGRP_MLME, GFP_KERNEL);
5940 	return;
5941 out:
5942 	nlmsg_free(msg);
5943 }
5944 
nl80211_validate_ap_phy_operation(struct cfg80211_ap_settings * params)5945 static int nl80211_validate_ap_phy_operation(struct cfg80211_ap_settings *params)
5946 {
5947 	struct ieee80211_channel *channel = params->chandef.chan;
5948 
5949 	if ((params->he_cap ||  params->he_oper) &&
5950 	    (channel->flags & IEEE80211_CHAN_NO_HE))
5951 		return -EOPNOTSUPP;
5952 
5953 	if ((params->eht_cap || params->eht_oper) &&
5954 	    (channel->flags & IEEE80211_CHAN_NO_EHT))
5955 		return -EOPNOTSUPP;
5956 
5957 	return 0;
5958 }
5959 
nl80211_start_ap(struct sk_buff * skb,struct genl_info * info)5960 static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
5961 {
5962 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5963 	unsigned int link_id = nl80211_link_id(info->attrs);
5964 	struct net_device *dev = info->user_ptr[1];
5965 	struct wireless_dev *wdev = dev->ieee80211_ptr;
5966 	struct cfg80211_ap_settings *params;
5967 	int err;
5968 
5969 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5970 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5971 		return -EOPNOTSUPP;
5972 
5973 	if (!rdev->ops->start_ap)
5974 		return -EOPNOTSUPP;
5975 
5976 	if (wdev->links[link_id].ap.beacon_interval)
5977 		return -EALREADY;
5978 
5979 	/* these are required for START_AP */
5980 	if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
5981 	    !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
5982 	    !info->attrs[NL80211_ATTR_BEACON_HEAD])
5983 		return -EINVAL;
5984 
5985 	params = kzalloc(sizeof(*params), GFP_KERNEL);
5986 	if (!params)
5987 		return -ENOMEM;
5988 
5989 	err = nl80211_parse_beacon(rdev, info->attrs, &params->beacon,
5990 				   info->extack);
5991 	if (err)
5992 		goto out;
5993 
5994 	params->beacon_interval =
5995 		nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
5996 	params->dtim_period =
5997 		nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
5998 
5999 	err = cfg80211_validate_beacon_int(rdev, dev->ieee80211_ptr->iftype,
6000 					   params->beacon_interval);
6001 	if (err)
6002 		goto out;
6003 
6004 	/*
6005 	 * In theory, some of these attributes should be required here
6006 	 * but since they were not used when the command was originally
6007 	 * added, keep them optional for old user space programs to let
6008 	 * them continue to work with drivers that do not need the
6009 	 * additional information -- drivers must check!
6010 	 */
6011 	if (info->attrs[NL80211_ATTR_SSID]) {
6012 		params->ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6013 		params->ssid_len =
6014 			nla_len(info->attrs[NL80211_ATTR_SSID]);
6015 		if (params->ssid_len == 0) {
6016 			err = -EINVAL;
6017 			goto out;
6018 		}
6019 
6020 		if (wdev->u.ap.ssid_len &&
6021 		    (wdev->u.ap.ssid_len != params->ssid_len ||
6022 		     memcmp(wdev->u.ap.ssid, params->ssid, params->ssid_len))) {
6023 			/* require identical SSID for MLO */
6024 			err = -EINVAL;
6025 			goto out;
6026 		}
6027 	} else if (wdev->valid_links) {
6028 		/* require SSID for MLO */
6029 		err = -EINVAL;
6030 		goto out;
6031 	}
6032 
6033 	if (info->attrs[NL80211_ATTR_HIDDEN_SSID])
6034 		params->hidden_ssid = nla_get_u32(
6035 			info->attrs[NL80211_ATTR_HIDDEN_SSID]);
6036 
6037 	params->privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
6038 
6039 	if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
6040 		params->auth_type = nla_get_u32(
6041 			info->attrs[NL80211_ATTR_AUTH_TYPE]);
6042 		if (!nl80211_valid_auth_type(rdev, params->auth_type,
6043 					     NL80211_CMD_START_AP)) {
6044 			err = -EINVAL;
6045 			goto out;
6046 		}
6047 	} else
6048 		params->auth_type = NL80211_AUTHTYPE_AUTOMATIC;
6049 
6050 	err = nl80211_crypto_settings(rdev, info, &params->crypto,
6051 				      NL80211_MAX_NR_CIPHER_SUITES);
6052 	if (err)
6053 		goto out;
6054 
6055 	if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
6056 		if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER)) {
6057 			err = -EOPNOTSUPP;
6058 			goto out;
6059 		}
6060 		params->inactivity_timeout = nla_get_u16(
6061 			info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
6062 	}
6063 
6064 	if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
6065 		if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
6066 			err = -EINVAL;
6067 			goto out;
6068 		}
6069 		params->p2p_ctwindow =
6070 			nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
6071 		if (params->p2p_ctwindow != 0 &&
6072 		    !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN)) {
6073 			err = -EINVAL;
6074 			goto out;
6075 		}
6076 	}
6077 
6078 	if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
6079 		u8 tmp;
6080 
6081 		if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
6082 			err = -EINVAL;
6083 			goto out;
6084 		}
6085 		tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
6086 		params->p2p_opp_ps = tmp;
6087 		if (params->p2p_opp_ps != 0 &&
6088 		    !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS)) {
6089 			err = -EINVAL;
6090 			goto out;
6091 		}
6092 	}
6093 
6094 	if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
6095 		err = nl80211_parse_chandef(rdev, info, &params->chandef);
6096 		if (err)
6097 			goto out;
6098 	} else if (wdev->valid_links) {
6099 		/* with MLD need to specify the channel configuration */
6100 		err = -EINVAL;
6101 		goto out;
6102 	} else if (wdev->u.ap.preset_chandef.chan) {
6103 		params->chandef = wdev->u.ap.preset_chandef;
6104 	} else if (!nl80211_get_ap_channel(rdev, params)) {
6105 		err = -EINVAL;
6106 		goto out;
6107 	}
6108 
6109 	if (info->attrs[NL80211_ATTR_PUNCT_BITMAP]) {
6110 		err = nl80211_parse_punct_bitmap(rdev, info,
6111 						 &params->chandef,
6112 						 &params->punct_bitmap);
6113 		if (err)
6114 			goto out;
6115 	}
6116 
6117 	if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &params->chandef,
6118 					   wdev->iftype)) {
6119 		err = -EINVAL;
6120 		goto out;
6121 	}
6122 
6123 	wdev_lock(wdev);
6124 
6125 	if (info->attrs[NL80211_ATTR_TX_RATES]) {
6126 		err = nl80211_parse_tx_bitrate_mask(info, info->attrs,
6127 						    NL80211_ATTR_TX_RATES,
6128 						    &params->beacon_rate,
6129 						    dev, false, link_id);
6130 		if (err)
6131 			goto out_unlock;
6132 
6133 		err = validate_beacon_tx_rate(rdev, params->chandef.chan->band,
6134 					      &params->beacon_rate);
6135 		if (err)
6136 			goto out_unlock;
6137 	}
6138 
6139 	if (info->attrs[NL80211_ATTR_SMPS_MODE]) {
6140 		params->smps_mode =
6141 			nla_get_u8(info->attrs[NL80211_ATTR_SMPS_MODE]);
6142 		switch (params->smps_mode) {
6143 		case NL80211_SMPS_OFF:
6144 			break;
6145 		case NL80211_SMPS_STATIC:
6146 			if (!(rdev->wiphy.features &
6147 			      NL80211_FEATURE_STATIC_SMPS)) {
6148 				err = -EINVAL;
6149 				goto out_unlock;
6150 			}
6151 			break;
6152 		case NL80211_SMPS_DYNAMIC:
6153 			if (!(rdev->wiphy.features &
6154 			      NL80211_FEATURE_DYNAMIC_SMPS)) {
6155 				err = -EINVAL;
6156 				goto out_unlock;
6157 			}
6158 			break;
6159 		default:
6160 			err = -EINVAL;
6161 			goto out_unlock;
6162 		}
6163 	} else {
6164 		params->smps_mode = NL80211_SMPS_OFF;
6165 	}
6166 
6167 	params->pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]);
6168 	if (params->pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ]) {
6169 		err = -EOPNOTSUPP;
6170 		goto out_unlock;
6171 	}
6172 
6173 	if (info->attrs[NL80211_ATTR_ACL_POLICY]) {
6174 		params->acl = parse_acl_data(&rdev->wiphy, info);
6175 		if (IS_ERR(params->acl)) {
6176 			err = PTR_ERR(params->acl);
6177 			params->acl = NULL;
6178 			goto out_unlock;
6179 		}
6180 	}
6181 
6182 	params->twt_responder =
6183 		    nla_get_flag(info->attrs[NL80211_ATTR_TWT_RESPONDER]);
6184 
6185 	if (info->attrs[NL80211_ATTR_HE_OBSS_PD]) {
6186 		err = nl80211_parse_he_obss_pd(
6187 					info->attrs[NL80211_ATTR_HE_OBSS_PD],
6188 					&params->he_obss_pd);
6189 		if (err)
6190 			goto out_unlock;
6191 	}
6192 
6193 	if (info->attrs[NL80211_ATTR_FILS_DISCOVERY]) {
6194 		err = nl80211_parse_fils_discovery(rdev,
6195 						   info->attrs[NL80211_ATTR_FILS_DISCOVERY],
6196 						   params);
6197 		if (err)
6198 			goto out_unlock;
6199 	}
6200 
6201 	if (info->attrs[NL80211_ATTR_UNSOL_BCAST_PROBE_RESP]) {
6202 		err = nl80211_parse_unsol_bcast_probe_resp(
6203 			rdev, info->attrs[NL80211_ATTR_UNSOL_BCAST_PROBE_RESP],
6204 			params);
6205 		if (err)
6206 			goto out_unlock;
6207 	}
6208 
6209 	if (info->attrs[NL80211_ATTR_MBSSID_CONFIG]) {
6210 		err = nl80211_parse_mbssid_config(&rdev->wiphy, dev,
6211 						  info->attrs[NL80211_ATTR_MBSSID_CONFIG],
6212 						  &params->mbssid_config,
6213 						  params->beacon.mbssid_ies ?
6214 							params->beacon.mbssid_ies->cnt :
6215 							0);
6216 		if (err)
6217 			goto out_unlock;
6218 	}
6219 
6220 	if (!params->mbssid_config.ema && params->beacon.rnr_ies) {
6221 		err = -EINVAL;
6222 		goto out_unlock;
6223 	}
6224 
6225 	err = nl80211_calculate_ap_params(params);
6226 	if (err)
6227 		goto out_unlock;
6228 
6229 	err = nl80211_validate_ap_phy_operation(params);
6230 	if (err)
6231 		goto out_unlock;
6232 
6233 	if (info->attrs[NL80211_ATTR_AP_SETTINGS_FLAGS])
6234 		params->flags = nla_get_u32(
6235 			info->attrs[NL80211_ATTR_AP_SETTINGS_FLAGS]);
6236 	else if (info->attrs[NL80211_ATTR_EXTERNAL_AUTH_SUPPORT])
6237 		params->flags |= NL80211_AP_SETTINGS_EXTERNAL_AUTH_SUPPORT;
6238 
6239 	if (wdev->conn_owner_nlportid &&
6240 	    info->attrs[NL80211_ATTR_SOCKET_OWNER] &&
6241 	    wdev->conn_owner_nlportid != info->snd_portid) {
6242 		err = -EINVAL;
6243 		goto out_unlock;
6244 	}
6245 
6246 	/* FIXME: validate MLO/link-id against driver capabilities */
6247 
6248 	err = rdev_start_ap(rdev, dev, params);
6249 	if (!err) {
6250 		wdev->links[link_id].ap.beacon_interval = params->beacon_interval;
6251 		wdev->links[link_id].ap.chandef = params->chandef;
6252 		wdev->u.ap.ssid_len = params->ssid_len;
6253 		memcpy(wdev->u.ap.ssid, params->ssid,
6254 		       params->ssid_len);
6255 
6256 		if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
6257 			wdev->conn_owner_nlportid = info->snd_portid;
6258 
6259 		nl80211_send_ap_started(wdev, link_id);
6260 	}
6261 out_unlock:
6262 	wdev_unlock(wdev);
6263 out:
6264 	kfree(params->acl);
6265 	kfree(params->beacon.mbssid_ies);
6266 	if (params->mbssid_config.tx_wdev &&
6267 	    params->mbssid_config.tx_wdev->netdev &&
6268 	    params->mbssid_config.tx_wdev->netdev != dev)
6269 		dev_put(params->mbssid_config.tx_wdev->netdev);
6270 	kfree(params->beacon.rnr_ies);
6271 	kfree(params);
6272 
6273 	return err;
6274 }
6275 
nl80211_set_beacon(struct sk_buff * skb,struct genl_info * info)6276 static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
6277 {
6278 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
6279 	unsigned int link_id = nl80211_link_id(info->attrs);
6280 	struct net_device *dev = info->user_ptr[1];
6281 	struct wireless_dev *wdev = dev->ieee80211_ptr;
6282 	struct cfg80211_beacon_data params;
6283 	int err;
6284 
6285 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
6286 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
6287 		return -EOPNOTSUPP;
6288 
6289 	if (!rdev->ops->change_beacon)
6290 		return -EOPNOTSUPP;
6291 
6292 	if (!wdev->links[link_id].ap.beacon_interval)
6293 		return -EINVAL;
6294 
6295 	err = nl80211_parse_beacon(rdev, info->attrs, &params, info->extack);
6296 	if (err)
6297 		goto out;
6298 
6299 	wdev_lock(wdev);
6300 	err = rdev_change_beacon(rdev, dev, &params);
6301 	wdev_unlock(wdev);
6302 
6303 out:
6304 	kfree(params.mbssid_ies);
6305 	kfree(params.rnr_ies);
6306 	return err;
6307 }
6308 
nl80211_stop_ap(struct sk_buff * skb,struct genl_info * info)6309 static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
6310 {
6311 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
6312 	unsigned int link_id = nl80211_link_id(info->attrs);
6313 	struct net_device *dev = info->user_ptr[1];
6314 
6315 	return cfg80211_stop_ap(rdev, dev, link_id, false);
6316 }
6317 
6318 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
6319 	[NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
6320 	[NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
6321 	[NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
6322 	[NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
6323 	[NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
6324 	[NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
6325 };
6326 
parse_station_flags(struct genl_info * info,enum nl80211_iftype iftype,struct station_parameters * params)6327 static int parse_station_flags(struct genl_info *info,
6328 			       enum nl80211_iftype iftype,
6329 			       struct station_parameters *params)
6330 {
6331 	struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
6332 	struct nlattr *nla;
6333 	int flag;
6334 
6335 	/*
6336 	 * Try parsing the new attribute first so userspace
6337 	 * can specify both for older kernels.
6338 	 */
6339 	nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
6340 	if (nla) {
6341 		struct nl80211_sta_flag_update *sta_flags;
6342 
6343 		sta_flags = nla_data(nla);
6344 		params->sta_flags_mask = sta_flags->mask;
6345 		params->sta_flags_set = sta_flags->set;
6346 		params->sta_flags_set &= params->sta_flags_mask;
6347 		if ((params->sta_flags_mask |
6348 		     params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
6349 			return -EINVAL;
6350 		return 0;
6351 	}
6352 
6353 	/* if present, parse the old attribute */
6354 
6355 	nla = info->attrs[NL80211_ATTR_STA_FLAGS];
6356 	if (!nla)
6357 		return 0;
6358 
6359 	if (nla_parse_nested_deprecated(flags, NL80211_STA_FLAG_MAX, nla, sta_flags_policy, info->extack))
6360 		return -EINVAL;
6361 
6362 	/*
6363 	 * Only allow certain flags for interface types so that
6364 	 * other attributes are silently ignored. Remember that
6365 	 * this is backward compatibility code with old userspace
6366 	 * and shouldn't be hit in other cases anyway.
6367 	 */
6368 	switch (iftype) {
6369 	case NL80211_IFTYPE_AP:
6370 	case NL80211_IFTYPE_AP_VLAN:
6371 	case NL80211_IFTYPE_P2P_GO:
6372 		params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
6373 					 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
6374 					 BIT(NL80211_STA_FLAG_WME) |
6375 					 BIT(NL80211_STA_FLAG_MFP);
6376 		break;
6377 	case NL80211_IFTYPE_P2P_CLIENT:
6378 	case NL80211_IFTYPE_STATION:
6379 		params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
6380 					 BIT(NL80211_STA_FLAG_TDLS_PEER);
6381 		break;
6382 	case NL80211_IFTYPE_MESH_POINT:
6383 		params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
6384 					 BIT(NL80211_STA_FLAG_MFP) |
6385 					 BIT(NL80211_STA_FLAG_AUTHORIZED);
6386 		break;
6387 	default:
6388 		return -EINVAL;
6389 	}
6390 
6391 	for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
6392 		if (flags[flag]) {
6393 			params->sta_flags_set |= (1<<flag);
6394 
6395 			/* no longer support new API additions in old API */
6396 			if (flag > NL80211_STA_FLAG_MAX_OLD_API)
6397 				return -EINVAL;
6398 		}
6399 	}
6400 
6401 	return 0;
6402 }
6403 
nl80211_put_sta_rate(struct sk_buff * msg,struct rate_info * info,int attr)6404 bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info, int attr)
6405 {
6406 	struct nlattr *rate;
6407 	u32 bitrate;
6408 	u16 bitrate_compat;
6409 	enum nl80211_rate_info rate_flg;
6410 
6411 	rate = nla_nest_start_noflag(msg, attr);
6412 	if (!rate)
6413 		return false;
6414 
6415 	/* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
6416 	bitrate = cfg80211_calculate_bitrate(info);
6417 	/* report 16-bit bitrate only if we can */
6418 	bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
6419 	if (bitrate > 0 &&
6420 	    nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
6421 		return false;
6422 	if (bitrate_compat > 0 &&
6423 	    nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
6424 		return false;
6425 
6426 	switch (info->bw) {
6427 	case RATE_INFO_BW_1:
6428 		rate_flg = NL80211_RATE_INFO_1_MHZ_WIDTH;
6429 		break;
6430 	case RATE_INFO_BW_2:
6431 		rate_flg = NL80211_RATE_INFO_2_MHZ_WIDTH;
6432 		break;
6433 	case RATE_INFO_BW_4:
6434 		rate_flg = NL80211_RATE_INFO_4_MHZ_WIDTH;
6435 		break;
6436 	case RATE_INFO_BW_5:
6437 		rate_flg = NL80211_RATE_INFO_5_MHZ_WIDTH;
6438 		break;
6439 	case RATE_INFO_BW_8:
6440 		rate_flg = NL80211_RATE_INFO_8_MHZ_WIDTH;
6441 		break;
6442 	case RATE_INFO_BW_10:
6443 		rate_flg = NL80211_RATE_INFO_10_MHZ_WIDTH;
6444 		break;
6445 	case RATE_INFO_BW_16:
6446 		rate_flg = NL80211_RATE_INFO_16_MHZ_WIDTH;
6447 		break;
6448 	default:
6449 		WARN_ON(1);
6450 		fallthrough;
6451 	case RATE_INFO_BW_20:
6452 		rate_flg = 0;
6453 		break;
6454 	case RATE_INFO_BW_40:
6455 		rate_flg = NL80211_RATE_INFO_40_MHZ_WIDTH;
6456 		break;
6457 	case RATE_INFO_BW_80:
6458 		rate_flg = NL80211_RATE_INFO_80_MHZ_WIDTH;
6459 		break;
6460 	case RATE_INFO_BW_160:
6461 		rate_flg = NL80211_RATE_INFO_160_MHZ_WIDTH;
6462 		break;
6463 	case RATE_INFO_BW_HE_RU:
6464 		rate_flg = 0;
6465 		WARN_ON(!(info->flags & RATE_INFO_FLAGS_HE_MCS));
6466 		break;
6467 	case RATE_INFO_BW_320:
6468 		rate_flg = NL80211_RATE_INFO_320_MHZ_WIDTH;
6469 		break;
6470 	case RATE_INFO_BW_EHT_RU:
6471 		rate_flg = 0;
6472 		WARN_ON(!(info->flags & RATE_INFO_FLAGS_EHT_MCS));
6473 		break;
6474 	}
6475 
6476 	if (rate_flg && nla_put_flag(msg, rate_flg))
6477 		return false;
6478 
6479 	if (info->flags & RATE_INFO_FLAGS_MCS) {
6480 		if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
6481 			return false;
6482 		if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
6483 		    nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
6484 			return false;
6485 	} else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
6486 		if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
6487 			return false;
6488 		if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
6489 			return false;
6490 		if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
6491 		    nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
6492 			return false;
6493 	} else if (info->flags & RATE_INFO_FLAGS_HE_MCS) {
6494 		if (nla_put_u8(msg, NL80211_RATE_INFO_HE_MCS, info->mcs))
6495 			return false;
6496 		if (nla_put_u8(msg, NL80211_RATE_INFO_HE_NSS, info->nss))
6497 			return false;
6498 		if (nla_put_u8(msg, NL80211_RATE_INFO_HE_GI, info->he_gi))
6499 			return false;
6500 		if (nla_put_u8(msg, NL80211_RATE_INFO_HE_DCM, info->he_dcm))
6501 			return false;
6502 		if (info->bw == RATE_INFO_BW_HE_RU &&
6503 		    nla_put_u8(msg, NL80211_RATE_INFO_HE_RU_ALLOC,
6504 			       info->he_ru_alloc))
6505 			return false;
6506 	} else if (info->flags & RATE_INFO_FLAGS_S1G_MCS) {
6507 		if (nla_put_u8(msg, NL80211_RATE_INFO_S1G_MCS, info->mcs))
6508 			return false;
6509 		if (nla_put_u8(msg, NL80211_RATE_INFO_S1G_NSS, info->nss))
6510 			return false;
6511 		if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
6512 		    nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
6513 			return false;
6514 	} else if (info->flags & RATE_INFO_FLAGS_EHT_MCS) {
6515 		if (nla_put_u8(msg, NL80211_RATE_INFO_EHT_MCS, info->mcs))
6516 			return false;
6517 		if (nla_put_u8(msg, NL80211_RATE_INFO_EHT_NSS, info->nss))
6518 			return false;
6519 		if (nla_put_u8(msg, NL80211_RATE_INFO_EHT_GI, info->eht_gi))
6520 			return false;
6521 		if (info->bw == RATE_INFO_BW_EHT_RU &&
6522 		    nla_put_u8(msg, NL80211_RATE_INFO_EHT_RU_ALLOC,
6523 			       info->eht_ru_alloc))
6524 			return false;
6525 	}
6526 
6527 	nla_nest_end(msg, rate);
6528 	return true;
6529 }
6530 
nl80211_put_signal(struct sk_buff * msg,u8 mask,s8 * signal,int id)6531 static bool nl80211_put_signal(struct sk_buff *msg, u8 mask, s8 *signal,
6532 			       int id)
6533 {
6534 	void *attr;
6535 	int i = 0;
6536 
6537 	if (!mask)
6538 		return true;
6539 
6540 	attr = nla_nest_start_noflag(msg, id);
6541 	if (!attr)
6542 		return false;
6543 
6544 	for (i = 0; i < IEEE80211_MAX_CHAINS; i++) {
6545 		if (!(mask & BIT(i)))
6546 			continue;
6547 
6548 		if (nla_put_u8(msg, i, signal[i]))
6549 			return false;
6550 	}
6551 
6552 	nla_nest_end(msg, attr);
6553 
6554 	return true;
6555 }
6556 
nl80211_send_station(struct sk_buff * msg,u32 cmd,u32 portid,u32 seq,int flags,struct cfg80211_registered_device * rdev,struct net_device * dev,const u8 * mac_addr,struct station_info * sinfo)6557 static int nl80211_send_station(struct sk_buff *msg, u32 cmd, u32 portid,
6558 				u32 seq, int flags,
6559 				struct cfg80211_registered_device *rdev,
6560 				struct net_device *dev,
6561 				const u8 *mac_addr, struct station_info *sinfo)
6562 {
6563 	void *hdr;
6564 	struct nlattr *sinfoattr, *bss_param;
6565 
6566 	hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
6567 	if (!hdr) {
6568 		cfg80211_sinfo_release_content(sinfo);
6569 		return -1;
6570 	}
6571 
6572 	if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
6573 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
6574 	    nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
6575 		goto nla_put_failure;
6576 
6577 	sinfoattr = nla_nest_start_noflag(msg, NL80211_ATTR_STA_INFO);
6578 	if (!sinfoattr)
6579 		goto nla_put_failure;
6580 
6581 #define PUT_SINFO(attr, memb, type) do {				\
6582 	BUILD_BUG_ON(sizeof(type) == sizeof(u64));			\
6583 	if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_ ## attr) &&	\
6584 	    nla_put_ ## type(msg, NL80211_STA_INFO_ ## attr,		\
6585 			     sinfo->memb))				\
6586 		goto nla_put_failure;					\
6587 	} while (0)
6588 #define PUT_SINFO_U64(attr, memb) do {					\
6589 	if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_ ## attr) &&	\
6590 	    nla_put_u64_64bit(msg, NL80211_STA_INFO_ ## attr,		\
6591 			      sinfo->memb, NL80211_STA_INFO_PAD))	\
6592 		goto nla_put_failure;					\
6593 	} while (0)
6594 
6595 	PUT_SINFO(CONNECTED_TIME, connected_time, u32);
6596 	PUT_SINFO(INACTIVE_TIME, inactive_time, u32);
6597 	PUT_SINFO_U64(ASSOC_AT_BOOTTIME, assoc_at);
6598 
6599 	if (sinfo->filled & (BIT_ULL(NL80211_STA_INFO_RX_BYTES) |
6600 			     BIT_ULL(NL80211_STA_INFO_RX_BYTES64)) &&
6601 	    nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
6602 			(u32)sinfo->rx_bytes))
6603 		goto nla_put_failure;
6604 
6605 	if (sinfo->filled & (BIT_ULL(NL80211_STA_INFO_TX_BYTES) |
6606 			     BIT_ULL(NL80211_STA_INFO_TX_BYTES64)) &&
6607 	    nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
6608 			(u32)sinfo->tx_bytes))
6609 		goto nla_put_failure;
6610 
6611 	PUT_SINFO_U64(RX_BYTES64, rx_bytes);
6612 	PUT_SINFO_U64(TX_BYTES64, tx_bytes);
6613 	PUT_SINFO(LLID, llid, u16);
6614 	PUT_SINFO(PLID, plid, u16);
6615 	PUT_SINFO(PLINK_STATE, plink_state, u8);
6616 	PUT_SINFO_U64(RX_DURATION, rx_duration);
6617 	PUT_SINFO_U64(TX_DURATION, tx_duration);
6618 
6619 	if (wiphy_ext_feature_isset(&rdev->wiphy,
6620 				    NL80211_EXT_FEATURE_AIRTIME_FAIRNESS))
6621 		PUT_SINFO(AIRTIME_WEIGHT, airtime_weight, u16);
6622 
6623 	switch (rdev->wiphy.signal_type) {
6624 	case CFG80211_SIGNAL_TYPE_MBM:
6625 		PUT_SINFO(SIGNAL, signal, u8);
6626 		PUT_SINFO(SIGNAL_AVG, signal_avg, u8);
6627 		break;
6628 	default:
6629 		break;
6630 	}
6631 	if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_CHAIN_SIGNAL)) {
6632 		if (!nl80211_put_signal(msg, sinfo->chains,
6633 					sinfo->chain_signal,
6634 					NL80211_STA_INFO_CHAIN_SIGNAL))
6635 			goto nla_put_failure;
6636 	}
6637 	if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_CHAIN_SIGNAL_AVG)) {
6638 		if (!nl80211_put_signal(msg, sinfo->chains,
6639 					sinfo->chain_signal_avg,
6640 					NL80211_STA_INFO_CHAIN_SIGNAL_AVG))
6641 			goto nla_put_failure;
6642 	}
6643 	if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_TX_BITRATE)) {
6644 		if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
6645 					  NL80211_STA_INFO_TX_BITRATE))
6646 			goto nla_put_failure;
6647 	}
6648 	if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_RX_BITRATE)) {
6649 		if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
6650 					  NL80211_STA_INFO_RX_BITRATE))
6651 			goto nla_put_failure;
6652 	}
6653 
6654 	PUT_SINFO(RX_PACKETS, rx_packets, u32);
6655 	PUT_SINFO(TX_PACKETS, tx_packets, u32);
6656 	PUT_SINFO(TX_RETRIES, tx_retries, u32);
6657 	PUT_SINFO(TX_FAILED, tx_failed, u32);
6658 	PUT_SINFO(EXPECTED_THROUGHPUT, expected_throughput, u32);
6659 	PUT_SINFO(AIRTIME_LINK_METRIC, airtime_link_metric, u32);
6660 	PUT_SINFO(BEACON_LOSS, beacon_loss_count, u32);
6661 	PUT_SINFO(LOCAL_PM, local_pm, u32);
6662 	PUT_SINFO(PEER_PM, peer_pm, u32);
6663 	PUT_SINFO(NONPEER_PM, nonpeer_pm, u32);
6664 	PUT_SINFO(CONNECTED_TO_GATE, connected_to_gate, u8);
6665 	PUT_SINFO(CONNECTED_TO_AS, connected_to_as, u8);
6666 
6667 	if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_BSS_PARAM)) {
6668 		bss_param = nla_nest_start_noflag(msg,
6669 						  NL80211_STA_INFO_BSS_PARAM);
6670 		if (!bss_param)
6671 			goto nla_put_failure;
6672 
6673 		if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
6674 		     nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
6675 		    ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
6676 		     nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
6677 		    ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
6678 		     nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
6679 		    nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
6680 			       sinfo->bss_param.dtim_period) ||
6681 		    nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
6682 				sinfo->bss_param.beacon_interval))
6683 			goto nla_put_failure;
6684 
6685 		nla_nest_end(msg, bss_param);
6686 	}
6687 	if ((sinfo->filled & BIT_ULL(NL80211_STA_INFO_STA_FLAGS)) &&
6688 	    nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
6689 		    sizeof(struct nl80211_sta_flag_update),
6690 		    &sinfo->sta_flags))
6691 		goto nla_put_failure;
6692 
6693 	PUT_SINFO_U64(T_OFFSET, t_offset);
6694 	PUT_SINFO_U64(RX_DROP_MISC, rx_dropped_misc);
6695 	PUT_SINFO_U64(BEACON_RX, rx_beacon);
6696 	PUT_SINFO(BEACON_SIGNAL_AVG, rx_beacon_signal_avg, u8);
6697 	PUT_SINFO(RX_MPDUS, rx_mpdu_count, u32);
6698 	PUT_SINFO(FCS_ERROR_COUNT, fcs_err_count, u32);
6699 	if (wiphy_ext_feature_isset(&rdev->wiphy,
6700 				    NL80211_EXT_FEATURE_ACK_SIGNAL_SUPPORT)) {
6701 		PUT_SINFO(ACK_SIGNAL, ack_signal, u8);
6702 		PUT_SINFO(ACK_SIGNAL_AVG, avg_ack_signal, s8);
6703 	}
6704 
6705 #undef PUT_SINFO
6706 #undef PUT_SINFO_U64
6707 
6708 	if (sinfo->pertid) {
6709 		struct nlattr *tidsattr;
6710 		int tid;
6711 
6712 		tidsattr = nla_nest_start_noflag(msg,
6713 						 NL80211_STA_INFO_TID_STATS);
6714 		if (!tidsattr)
6715 			goto nla_put_failure;
6716 
6717 		for (tid = 0; tid < IEEE80211_NUM_TIDS + 1; tid++) {
6718 			struct cfg80211_tid_stats *tidstats;
6719 			struct nlattr *tidattr;
6720 
6721 			tidstats = &sinfo->pertid[tid];
6722 
6723 			if (!tidstats->filled)
6724 				continue;
6725 
6726 			tidattr = nla_nest_start_noflag(msg, tid + 1);
6727 			if (!tidattr)
6728 				goto nla_put_failure;
6729 
6730 #define PUT_TIDVAL_U64(attr, memb) do {					\
6731 	if (tidstats->filled & BIT(NL80211_TID_STATS_ ## attr) &&	\
6732 	    nla_put_u64_64bit(msg, NL80211_TID_STATS_ ## attr,		\
6733 			      tidstats->memb, NL80211_TID_STATS_PAD))	\
6734 		goto nla_put_failure;					\
6735 	} while (0)
6736 
6737 			PUT_TIDVAL_U64(RX_MSDU, rx_msdu);
6738 			PUT_TIDVAL_U64(TX_MSDU, tx_msdu);
6739 			PUT_TIDVAL_U64(TX_MSDU_RETRIES, tx_msdu_retries);
6740 			PUT_TIDVAL_U64(TX_MSDU_FAILED, tx_msdu_failed);
6741 
6742 #undef PUT_TIDVAL_U64
6743 			if ((tidstats->filled &
6744 			     BIT(NL80211_TID_STATS_TXQ_STATS)) &&
6745 			    !nl80211_put_txq_stats(msg, &tidstats->txq_stats,
6746 						   NL80211_TID_STATS_TXQ_STATS))
6747 				goto nla_put_failure;
6748 
6749 			nla_nest_end(msg, tidattr);
6750 		}
6751 
6752 		nla_nest_end(msg, tidsattr);
6753 	}
6754 
6755 	nla_nest_end(msg, sinfoattr);
6756 
6757 	if (sinfo->assoc_req_ies_len &&
6758 	    nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
6759 		    sinfo->assoc_req_ies))
6760 		goto nla_put_failure;
6761 
6762 	if (sinfo->assoc_resp_ies_len &&
6763 	    nla_put(msg, NL80211_ATTR_RESP_IE, sinfo->assoc_resp_ies_len,
6764 		    sinfo->assoc_resp_ies))
6765 		goto nla_put_failure;
6766 
6767 	if (sinfo->mlo_params_valid) {
6768 		if (nla_put_u8(msg, NL80211_ATTR_MLO_LINK_ID,
6769 			       sinfo->assoc_link_id))
6770 			goto nla_put_failure;
6771 
6772 		if (!is_zero_ether_addr(sinfo->mld_addr) &&
6773 		    nla_put(msg, NL80211_ATTR_MLD_ADDR, ETH_ALEN,
6774 			    sinfo->mld_addr))
6775 			goto nla_put_failure;
6776 	}
6777 
6778 	cfg80211_sinfo_release_content(sinfo);
6779 	genlmsg_end(msg, hdr);
6780 	return 0;
6781 
6782  nla_put_failure:
6783 	cfg80211_sinfo_release_content(sinfo);
6784 	genlmsg_cancel(msg, hdr);
6785 	return -EMSGSIZE;
6786 }
6787 
nl80211_dump_station(struct sk_buff * skb,struct netlink_callback * cb)6788 static int nl80211_dump_station(struct sk_buff *skb,
6789 				struct netlink_callback *cb)
6790 {
6791 	struct station_info sinfo;
6792 	struct cfg80211_registered_device *rdev;
6793 	struct wireless_dev *wdev;
6794 	u8 mac_addr[ETH_ALEN];
6795 	int sta_idx = cb->args[2];
6796 	int err;
6797 
6798 	err = nl80211_prepare_wdev_dump(cb, &rdev, &wdev, NULL);
6799 	if (err)
6800 		return err;
6801 	/* nl80211_prepare_wdev_dump acquired it in the successful case */
6802 	__acquire(&rdev->wiphy.mtx);
6803 
6804 	if (!wdev->netdev) {
6805 		err = -EINVAL;
6806 		goto out_err;
6807 	}
6808 
6809 	if (!rdev->ops->dump_station) {
6810 		err = -EOPNOTSUPP;
6811 		goto out_err;
6812 	}
6813 
6814 	while (1) {
6815 		memset(&sinfo, 0, sizeof(sinfo));
6816 		err = rdev_dump_station(rdev, wdev->netdev, sta_idx,
6817 					mac_addr, &sinfo);
6818 		if (err == -ENOENT)
6819 			break;
6820 		if (err)
6821 			goto out_err;
6822 
6823 		if (nl80211_send_station(skb, NL80211_CMD_NEW_STATION,
6824 				NETLINK_CB(cb->skb).portid,
6825 				cb->nlh->nlmsg_seq, NLM_F_MULTI,
6826 				rdev, wdev->netdev, mac_addr,
6827 				&sinfo) < 0)
6828 			goto out;
6829 
6830 		sta_idx++;
6831 	}
6832 
6833  out:
6834 	cb->args[2] = sta_idx;
6835 	err = skb->len;
6836  out_err:
6837 	wiphy_unlock(&rdev->wiphy);
6838 
6839 	return err;
6840 }
6841 
nl80211_get_station(struct sk_buff * skb,struct genl_info * info)6842 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
6843 {
6844 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
6845 	struct net_device *dev = info->user_ptr[1];
6846 	struct station_info sinfo;
6847 	struct sk_buff *msg;
6848 	u8 *mac_addr = NULL;
6849 	int err;
6850 
6851 	memset(&sinfo, 0, sizeof(sinfo));
6852 
6853 	if (!info->attrs[NL80211_ATTR_MAC])
6854 		return -EINVAL;
6855 
6856 	mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
6857 
6858 	if (!rdev->ops->get_station)
6859 		return -EOPNOTSUPP;
6860 
6861 	err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
6862 	if (err)
6863 		return err;
6864 
6865 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6866 	if (!msg) {
6867 		cfg80211_sinfo_release_content(&sinfo);
6868 		return -ENOMEM;
6869 	}
6870 
6871 	if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION,
6872 				 info->snd_portid, info->snd_seq, 0,
6873 				 rdev, dev, mac_addr, &sinfo) < 0) {
6874 		nlmsg_free(msg);
6875 		return -ENOBUFS;
6876 	}
6877 
6878 	return genlmsg_reply(msg, info);
6879 }
6880 
cfg80211_check_station_change(struct wiphy * wiphy,struct station_parameters * params,enum cfg80211_station_type statype)6881 int cfg80211_check_station_change(struct wiphy *wiphy,
6882 				  struct station_parameters *params,
6883 				  enum cfg80211_station_type statype)
6884 {
6885 	if (params->listen_interval != -1 &&
6886 	    statype != CFG80211_STA_AP_CLIENT_UNASSOC)
6887 		return -EINVAL;
6888 
6889 	if (params->support_p2p_ps != -1 &&
6890 	    statype != CFG80211_STA_AP_CLIENT_UNASSOC)
6891 		return -EINVAL;
6892 
6893 	if (params->aid &&
6894 	    !(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) &&
6895 	    statype != CFG80211_STA_AP_CLIENT_UNASSOC)
6896 		return -EINVAL;
6897 
6898 	/* When you run into this, adjust the code below for the new flag */
6899 	BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
6900 
6901 	switch (statype) {
6902 	case CFG80211_STA_MESH_PEER_KERNEL:
6903 	case CFG80211_STA_MESH_PEER_USER:
6904 		/*
6905 		 * No ignoring the TDLS flag here -- the userspace mesh
6906 		 * code doesn't have the bug of including TDLS in the
6907 		 * mask everywhere.
6908 		 */
6909 		if (params->sta_flags_mask &
6910 				~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
6911 				  BIT(NL80211_STA_FLAG_MFP) |
6912 				  BIT(NL80211_STA_FLAG_AUTHORIZED)))
6913 			return -EINVAL;
6914 		break;
6915 	case CFG80211_STA_TDLS_PEER_SETUP:
6916 	case CFG80211_STA_TDLS_PEER_ACTIVE:
6917 		if (!(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
6918 			return -EINVAL;
6919 		/* ignore since it can't change */
6920 		params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
6921 		break;
6922 	default:
6923 		/* disallow mesh-specific things */
6924 		if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION)
6925 			return -EINVAL;
6926 		if (params->local_pm)
6927 			return -EINVAL;
6928 		if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
6929 			return -EINVAL;
6930 	}
6931 
6932 	if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
6933 	    statype != CFG80211_STA_TDLS_PEER_ACTIVE) {
6934 		/* TDLS can't be set, ... */
6935 		if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
6936 			return -EINVAL;
6937 		/*
6938 		 * ... but don't bother the driver with it. This works around
6939 		 * a hostapd/wpa_supplicant issue -- it always includes the
6940 		 * TLDS_PEER flag in the mask even for AP mode.
6941 		 */
6942 		params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
6943 	}
6944 
6945 	if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
6946 	    statype != CFG80211_STA_AP_CLIENT_UNASSOC) {
6947 		/* reject other things that can't change */
6948 		if (params->sta_modify_mask & STATION_PARAM_APPLY_UAPSD)
6949 			return -EINVAL;
6950 		if (params->sta_modify_mask & STATION_PARAM_APPLY_CAPABILITY)
6951 			return -EINVAL;
6952 		if (params->link_sta_params.supported_rates)
6953 			return -EINVAL;
6954 		if (params->ext_capab || params->link_sta_params.ht_capa ||
6955 		    params->link_sta_params.vht_capa ||
6956 		    params->link_sta_params.he_capa ||
6957 		    params->link_sta_params.eht_capa)
6958 			return -EINVAL;
6959 	}
6960 
6961 	if (statype != CFG80211_STA_AP_CLIENT &&
6962 	    statype != CFG80211_STA_AP_CLIENT_UNASSOC) {
6963 		if (params->vlan)
6964 			return -EINVAL;
6965 	}
6966 
6967 	switch (statype) {
6968 	case CFG80211_STA_AP_MLME_CLIENT:
6969 		/* Use this only for authorizing/unauthorizing a station */
6970 		if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED)))
6971 			return -EOPNOTSUPP;
6972 		break;
6973 	case CFG80211_STA_AP_CLIENT:
6974 	case CFG80211_STA_AP_CLIENT_UNASSOC:
6975 		/* accept only the listed bits */
6976 		if (params->sta_flags_mask &
6977 				~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
6978 				  BIT(NL80211_STA_FLAG_AUTHENTICATED) |
6979 				  BIT(NL80211_STA_FLAG_ASSOCIATED) |
6980 				  BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
6981 				  BIT(NL80211_STA_FLAG_WME) |
6982 				  BIT(NL80211_STA_FLAG_MFP)))
6983 			return -EINVAL;
6984 
6985 		/* but authenticated/associated only if driver handles it */
6986 		if (!(wiphy->features & NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
6987 		    params->sta_flags_mask &
6988 				(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
6989 				 BIT(NL80211_STA_FLAG_ASSOCIATED)))
6990 			return -EINVAL;
6991 		break;
6992 	case CFG80211_STA_IBSS:
6993 	case CFG80211_STA_AP_STA:
6994 		/* reject any changes other than AUTHORIZED */
6995 		if (params->sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
6996 			return -EINVAL;
6997 		break;
6998 	case CFG80211_STA_TDLS_PEER_SETUP:
6999 		/* reject any changes other than AUTHORIZED or WME */
7000 		if (params->sta_flags_mask & ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
7001 					       BIT(NL80211_STA_FLAG_WME)))
7002 			return -EINVAL;
7003 		/* force (at least) rates when authorizing */
7004 		if (params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED) &&
7005 		    !params->link_sta_params.supported_rates)
7006 			return -EINVAL;
7007 		break;
7008 	case CFG80211_STA_TDLS_PEER_ACTIVE:
7009 		/* reject any changes */
7010 		return -EINVAL;
7011 	case CFG80211_STA_MESH_PEER_KERNEL:
7012 		if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
7013 			return -EINVAL;
7014 		break;
7015 	case CFG80211_STA_MESH_PEER_USER:
7016 		if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION &&
7017 		    params->plink_action != NL80211_PLINK_ACTION_BLOCK)
7018 			return -EINVAL;
7019 		break;
7020 	}
7021 
7022 	/*
7023 	 * Older kernel versions ignored this attribute entirely, so don't
7024 	 * reject attempts to update it but mark it as unused instead so the
7025 	 * driver won't look at the data.
7026 	 */
7027 	if (statype != CFG80211_STA_AP_CLIENT_UNASSOC &&
7028 	    statype != CFG80211_STA_TDLS_PEER_SETUP)
7029 		params->link_sta_params.opmode_notif_used = false;
7030 
7031 	return 0;
7032 }
7033 EXPORT_SYMBOL(cfg80211_check_station_change);
7034 
7035 /*
7036  * Get vlan interface making sure it is running and on the right wiphy.
7037  */
get_vlan(struct genl_info * info,struct cfg80211_registered_device * rdev)7038 static struct net_device *get_vlan(struct genl_info *info,
7039 				   struct cfg80211_registered_device *rdev)
7040 {
7041 	struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
7042 	struct net_device *v;
7043 	int ret;
7044 
7045 	if (!vlanattr)
7046 		return NULL;
7047 
7048 	v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
7049 	if (!v)
7050 		return ERR_PTR(-ENODEV);
7051 
7052 	if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
7053 		ret = -EINVAL;
7054 		goto error;
7055 	}
7056 
7057 	if (v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
7058 	    v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
7059 	    v->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
7060 		ret = -EINVAL;
7061 		goto error;
7062 	}
7063 
7064 	if (!netif_running(v)) {
7065 		ret = -ENETDOWN;
7066 		goto error;
7067 	}
7068 
7069 	return v;
7070  error:
7071 	dev_put(v);
7072 	return ERR_PTR(ret);
7073 }
7074 
nl80211_parse_sta_wme(struct genl_info * info,struct station_parameters * params)7075 static int nl80211_parse_sta_wme(struct genl_info *info,
7076 				 struct station_parameters *params)
7077 {
7078 	struct nlattr *tb[NL80211_STA_WME_MAX + 1];
7079 	struct nlattr *nla;
7080 	int err;
7081 
7082 	/* parse WME attributes if present */
7083 	if (!info->attrs[NL80211_ATTR_STA_WME])
7084 		return 0;
7085 
7086 	nla = info->attrs[NL80211_ATTR_STA_WME];
7087 	err = nla_parse_nested_deprecated(tb, NL80211_STA_WME_MAX, nla,
7088 					  nl80211_sta_wme_policy,
7089 					  info->extack);
7090 	if (err)
7091 		return err;
7092 
7093 	if (tb[NL80211_STA_WME_UAPSD_QUEUES])
7094 		params->uapsd_queues = nla_get_u8(
7095 			tb[NL80211_STA_WME_UAPSD_QUEUES]);
7096 	if (params->uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
7097 		return -EINVAL;
7098 
7099 	if (tb[NL80211_STA_WME_MAX_SP])
7100 		params->max_sp = nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
7101 
7102 	if (params->max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
7103 		return -EINVAL;
7104 
7105 	params->sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
7106 
7107 	return 0;
7108 }
7109 
nl80211_parse_sta_channel_info(struct genl_info * info,struct station_parameters * params)7110 static int nl80211_parse_sta_channel_info(struct genl_info *info,
7111 				      struct station_parameters *params)
7112 {
7113 	if (info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]) {
7114 		params->supported_channels =
7115 		     nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
7116 		params->supported_channels_len =
7117 		     nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
7118 		/*
7119 		 * Need to include at least one (first channel, number of
7120 		 * channels) tuple for each subband (checked in policy),
7121 		 * and must have proper tuples for the rest of the data as well.
7122 		 */
7123 		if (params->supported_channels_len % 2)
7124 			return -EINVAL;
7125 	}
7126 
7127 	if (info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]) {
7128 		params->supported_oper_classes =
7129 		 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
7130 		params->supported_oper_classes_len =
7131 		  nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
7132 	}
7133 	return 0;
7134 }
7135 
nl80211_set_station_tdls(struct genl_info * info,struct station_parameters * params)7136 static int nl80211_set_station_tdls(struct genl_info *info,
7137 				    struct station_parameters *params)
7138 {
7139 	int err;
7140 	/* Dummy STA entry gets updated once the peer capabilities are known */
7141 	if (info->attrs[NL80211_ATTR_PEER_AID])
7142 		params->aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
7143 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
7144 		params->link_sta_params.ht_capa =
7145 			nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
7146 	if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
7147 		params->link_sta_params.vht_capa =
7148 			nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
7149 	if (info->attrs[NL80211_ATTR_HE_CAPABILITY]) {
7150 		params->link_sta_params.he_capa =
7151 			nla_data(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
7152 		params->link_sta_params.he_capa_len =
7153 			nla_len(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
7154 
7155 		if (info->attrs[NL80211_ATTR_EHT_CAPABILITY]) {
7156 			params->link_sta_params.eht_capa =
7157 				nla_data(info->attrs[NL80211_ATTR_EHT_CAPABILITY]);
7158 			params->link_sta_params.eht_capa_len =
7159 				nla_len(info->attrs[NL80211_ATTR_EHT_CAPABILITY]);
7160 
7161 			if (!ieee80211_eht_capa_size_ok((const u8 *)params->link_sta_params.he_capa,
7162 							(const u8 *)params->link_sta_params.eht_capa,
7163 							params->link_sta_params.eht_capa_len,
7164 							false))
7165 				return -EINVAL;
7166 		}
7167 	}
7168 
7169 	err = nl80211_parse_sta_channel_info(info, params);
7170 	if (err)
7171 		return err;
7172 
7173 	return nl80211_parse_sta_wme(info, params);
7174 }
7175 
nl80211_parse_sta_txpower_setting(struct genl_info * info,struct sta_txpwr * txpwr,bool * txpwr_set)7176 static int nl80211_parse_sta_txpower_setting(struct genl_info *info,
7177 					     struct sta_txpwr *txpwr,
7178 					     bool *txpwr_set)
7179 {
7180 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
7181 	int idx;
7182 
7183 	if (info->attrs[NL80211_ATTR_STA_TX_POWER_SETTING]) {
7184 		if (!rdev->ops->set_tx_power ||
7185 		    !wiphy_ext_feature_isset(&rdev->wiphy,
7186 					 NL80211_EXT_FEATURE_STA_TX_PWR))
7187 			return -EOPNOTSUPP;
7188 
7189 		idx = NL80211_ATTR_STA_TX_POWER_SETTING;
7190 		txpwr->type = nla_get_u8(info->attrs[idx]);
7191 
7192 		if (txpwr->type == NL80211_TX_POWER_LIMITED) {
7193 			idx = NL80211_ATTR_STA_TX_POWER;
7194 
7195 			if (info->attrs[idx])
7196 				txpwr->power = nla_get_s16(info->attrs[idx]);
7197 			else
7198 				return -EINVAL;
7199 		}
7200 
7201 		*txpwr_set = true;
7202 	} else {
7203 		*txpwr_set = false;
7204 	}
7205 
7206 	return 0;
7207 }
7208 
nl80211_set_station(struct sk_buff * skb,struct genl_info * info)7209 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
7210 {
7211 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
7212 	struct net_device *dev = info->user_ptr[1];
7213 	struct station_parameters params;
7214 	u8 *mac_addr;
7215 	int err;
7216 
7217 	memset(&params, 0, sizeof(params));
7218 
7219 	if (!rdev->ops->change_station)
7220 		return -EOPNOTSUPP;
7221 
7222 	/*
7223 	 * AID and listen_interval properties can be set only for unassociated
7224 	 * station. Include these parameters here and will check them in
7225 	 * cfg80211_check_station_change().
7226 	 */
7227 	if (info->attrs[NL80211_ATTR_STA_AID])
7228 		params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
7229 
7230 	if (info->attrs[NL80211_ATTR_VLAN_ID])
7231 		params.vlan_id = nla_get_u16(info->attrs[NL80211_ATTR_VLAN_ID]);
7232 
7233 	if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
7234 		params.listen_interval =
7235 		     nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
7236 	else
7237 		params.listen_interval = -1;
7238 
7239 	if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS])
7240 		params.support_p2p_ps =
7241 			nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]);
7242 	else
7243 		params.support_p2p_ps = -1;
7244 
7245 	if (!info->attrs[NL80211_ATTR_MAC])
7246 		return -EINVAL;
7247 
7248 	params.link_sta_params.link_id =
7249 		nl80211_link_id_or_invalid(info->attrs);
7250 
7251 	if (info->attrs[NL80211_ATTR_MLD_ADDR]) {
7252 		/* If MLD_ADDR attribute is set then this is an MLD station
7253 		 * and the MLD_ADDR attribute holds the MLD address and the
7254 		 * MAC attribute holds for the LINK address.
7255 		 * In that case, the link_id is also expected to be valid.
7256 		 */
7257 		if (params.link_sta_params.link_id < 0)
7258 			return -EINVAL;
7259 
7260 		mac_addr = nla_data(info->attrs[NL80211_ATTR_MLD_ADDR]);
7261 		params.link_sta_params.mld_mac = mac_addr;
7262 		params.link_sta_params.link_mac =
7263 			nla_data(info->attrs[NL80211_ATTR_MAC]);
7264 		if (!is_valid_ether_addr(params.link_sta_params.link_mac))
7265 			return -EINVAL;
7266 	} else {
7267 		mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
7268 	}
7269 
7270 
7271 	if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
7272 		params.link_sta_params.supported_rates =
7273 			nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
7274 		params.link_sta_params.supported_rates_len =
7275 			nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
7276 	}
7277 
7278 	if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
7279 		params.capability =
7280 			nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
7281 		params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
7282 	}
7283 
7284 	if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
7285 		params.ext_capab =
7286 			nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
7287 		params.ext_capab_len =
7288 			nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
7289 	}
7290 
7291 	if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
7292 		return -EINVAL;
7293 
7294 	if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
7295 		params.plink_action =
7296 			nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
7297 
7298 	if (info->attrs[NL80211_ATTR_STA_PLINK_STATE]) {
7299 		params.plink_state =
7300 			nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
7301 		if (info->attrs[NL80211_ATTR_MESH_PEER_AID])
7302 			params.peer_aid = nla_get_u16(
7303 				info->attrs[NL80211_ATTR_MESH_PEER_AID]);
7304 		params.sta_modify_mask |= STATION_PARAM_APPLY_PLINK_STATE;
7305 	}
7306 
7307 	if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE])
7308 		params.local_pm = nla_get_u32(
7309 			info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]);
7310 
7311 	if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) {
7312 		params.link_sta_params.opmode_notif_used = true;
7313 		params.link_sta_params.opmode_notif =
7314 			nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]);
7315 	}
7316 
7317 	if (info->attrs[NL80211_ATTR_HE_6GHZ_CAPABILITY])
7318 		params.link_sta_params.he_6ghz_capa =
7319 			nla_data(info->attrs[NL80211_ATTR_HE_6GHZ_CAPABILITY]);
7320 
7321 	if (info->attrs[NL80211_ATTR_AIRTIME_WEIGHT])
7322 		params.airtime_weight =
7323 			nla_get_u16(info->attrs[NL80211_ATTR_AIRTIME_WEIGHT]);
7324 
7325 	if (params.airtime_weight &&
7326 	    !wiphy_ext_feature_isset(&rdev->wiphy,
7327 				     NL80211_EXT_FEATURE_AIRTIME_FAIRNESS))
7328 		return -EOPNOTSUPP;
7329 
7330 	err = nl80211_parse_sta_txpower_setting(info,
7331 						&params.link_sta_params.txpwr,
7332 						&params.link_sta_params.txpwr_set);
7333 	if (err)
7334 		return err;
7335 
7336 	/* Include parameters for TDLS peer (will check later) */
7337 	err = nl80211_set_station_tdls(info, &params);
7338 	if (err)
7339 		return err;
7340 
7341 	params.vlan = get_vlan(info, rdev);
7342 	if (IS_ERR(params.vlan))
7343 		return PTR_ERR(params.vlan);
7344 
7345 	switch (dev->ieee80211_ptr->iftype) {
7346 	case NL80211_IFTYPE_AP:
7347 	case NL80211_IFTYPE_AP_VLAN:
7348 	case NL80211_IFTYPE_P2P_GO:
7349 	case NL80211_IFTYPE_P2P_CLIENT:
7350 	case NL80211_IFTYPE_STATION:
7351 	case NL80211_IFTYPE_ADHOC:
7352 	case NL80211_IFTYPE_MESH_POINT:
7353 		break;
7354 	default:
7355 		err = -EOPNOTSUPP;
7356 		goto out_put_vlan;
7357 	}
7358 
7359 	/* driver will call cfg80211_check_station_change() */
7360 	wdev_lock(dev->ieee80211_ptr);
7361 	err = rdev_change_station(rdev, dev, mac_addr, &params);
7362 	wdev_unlock(dev->ieee80211_ptr);
7363 
7364  out_put_vlan:
7365 	dev_put(params.vlan);
7366 
7367 	return err;
7368 }
7369 
nl80211_new_station(struct sk_buff * skb,struct genl_info * info)7370 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
7371 {
7372 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
7373 	int err;
7374 	struct net_device *dev = info->user_ptr[1];
7375 	struct wireless_dev *wdev = dev->ieee80211_ptr;
7376 	struct station_parameters params;
7377 	u8 *mac_addr = NULL;
7378 	u32 auth_assoc = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
7379 			 BIT(NL80211_STA_FLAG_ASSOCIATED);
7380 
7381 	memset(&params, 0, sizeof(params));
7382 
7383 	if (!rdev->ops->add_station)
7384 		return -EOPNOTSUPP;
7385 
7386 	if (!info->attrs[NL80211_ATTR_MAC])
7387 		return -EINVAL;
7388 
7389 	if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
7390 		return -EINVAL;
7391 
7392 	if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
7393 		return -EINVAL;
7394 
7395 	if (!info->attrs[NL80211_ATTR_STA_AID] &&
7396 	    !info->attrs[NL80211_ATTR_PEER_AID])
7397 		return -EINVAL;
7398 
7399 	params.link_sta_params.link_id =
7400 		nl80211_link_id_or_invalid(info->attrs);
7401 
7402 	if (info->attrs[NL80211_ATTR_MLD_ADDR]) {
7403 		mac_addr = nla_data(info->attrs[NL80211_ATTR_MLD_ADDR]);
7404 		params.link_sta_params.mld_mac = mac_addr;
7405 		params.link_sta_params.link_mac =
7406 			nla_data(info->attrs[NL80211_ATTR_MAC]);
7407 		if (!is_valid_ether_addr(params.link_sta_params.link_mac))
7408 			return -EINVAL;
7409 	} else {
7410 		mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
7411 	}
7412 
7413 	params.link_sta_params.supported_rates =
7414 		nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
7415 	params.link_sta_params.supported_rates_len =
7416 		nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
7417 	params.listen_interval =
7418 		nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
7419 
7420 	if (info->attrs[NL80211_ATTR_VLAN_ID])
7421 		params.vlan_id = nla_get_u16(info->attrs[NL80211_ATTR_VLAN_ID]);
7422 
7423 	if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]) {
7424 		params.support_p2p_ps =
7425 			nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]);
7426 	} else {
7427 		/*
7428 		 * if not specified, assume it's supported for P2P GO interface,
7429 		 * and is NOT supported for AP interface
7430 		 */
7431 		params.support_p2p_ps =
7432 			dev->ieee80211_ptr->iftype == NL80211_IFTYPE_P2P_GO;
7433 	}
7434 
7435 	if (info->attrs[NL80211_ATTR_PEER_AID])
7436 		params.aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
7437 	else
7438 		params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
7439 
7440 	if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
7441 		params.capability =
7442 			nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
7443 		params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
7444 	}
7445 
7446 	if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
7447 		params.ext_capab =
7448 			nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
7449 		params.ext_capab_len =
7450 			nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
7451 	}
7452 
7453 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
7454 		params.link_sta_params.ht_capa =
7455 			nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
7456 
7457 	if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
7458 		params.link_sta_params.vht_capa =
7459 			nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
7460 
7461 	if (info->attrs[NL80211_ATTR_HE_CAPABILITY]) {
7462 		params.link_sta_params.he_capa =
7463 			nla_data(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
7464 		params.link_sta_params.he_capa_len =
7465 			nla_len(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
7466 
7467 		if (info->attrs[NL80211_ATTR_EHT_CAPABILITY]) {
7468 			params.link_sta_params.eht_capa =
7469 				nla_data(info->attrs[NL80211_ATTR_EHT_CAPABILITY]);
7470 			params.link_sta_params.eht_capa_len =
7471 				nla_len(info->attrs[NL80211_ATTR_EHT_CAPABILITY]);
7472 
7473 			if (!ieee80211_eht_capa_size_ok((const u8 *)params.link_sta_params.he_capa,
7474 							(const u8 *)params.link_sta_params.eht_capa,
7475 							params.link_sta_params.eht_capa_len,
7476 							false))
7477 				return -EINVAL;
7478 		}
7479 	}
7480 
7481 	if (info->attrs[NL80211_ATTR_HE_6GHZ_CAPABILITY])
7482 		params.link_sta_params.he_6ghz_capa =
7483 			nla_data(info->attrs[NL80211_ATTR_HE_6GHZ_CAPABILITY]);
7484 
7485 	if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) {
7486 		params.link_sta_params.opmode_notif_used = true;
7487 		params.link_sta_params.opmode_notif =
7488 			nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]);
7489 	}
7490 
7491 	if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
7492 		params.plink_action =
7493 			nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
7494 
7495 	if (info->attrs[NL80211_ATTR_AIRTIME_WEIGHT])
7496 		params.airtime_weight =
7497 			nla_get_u16(info->attrs[NL80211_ATTR_AIRTIME_WEIGHT]);
7498 
7499 	if (params.airtime_weight &&
7500 	    !wiphy_ext_feature_isset(&rdev->wiphy,
7501 				     NL80211_EXT_FEATURE_AIRTIME_FAIRNESS))
7502 		return -EOPNOTSUPP;
7503 
7504 	err = nl80211_parse_sta_txpower_setting(info,
7505 						&params.link_sta_params.txpwr,
7506 						&params.link_sta_params.txpwr_set);
7507 	if (err)
7508 		return err;
7509 
7510 	err = nl80211_parse_sta_channel_info(info, &params);
7511 	if (err)
7512 		return err;
7513 
7514 	err = nl80211_parse_sta_wme(info, &params);
7515 	if (err)
7516 		return err;
7517 
7518 	if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
7519 		return -EINVAL;
7520 
7521 	/* HT/VHT requires QoS, but if we don't have that just ignore HT/VHT
7522 	 * as userspace might just pass through the capabilities from the IEs
7523 	 * directly, rather than enforcing this restriction and returning an
7524 	 * error in this case.
7525 	 */
7526 	if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME))) {
7527 		params.link_sta_params.ht_capa = NULL;
7528 		params.link_sta_params.vht_capa = NULL;
7529 
7530 		/* HE and EHT require WME */
7531 		if (params.link_sta_params.he_capa_len ||
7532 		    params.link_sta_params.he_6ghz_capa ||
7533 		    params.link_sta_params.eht_capa_len)
7534 			return -EINVAL;
7535 	}
7536 
7537 	/* Ensure that HT/VHT capabilities are not set for 6 GHz HE STA */
7538 	if (params.link_sta_params.he_6ghz_capa &&
7539 	    (params.link_sta_params.ht_capa || params.link_sta_params.vht_capa))
7540 		return -EINVAL;
7541 
7542 	/* When you run into this, adjust the code below for the new flag */
7543 	BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
7544 
7545 	switch (dev->ieee80211_ptr->iftype) {
7546 	case NL80211_IFTYPE_AP:
7547 	case NL80211_IFTYPE_AP_VLAN:
7548 	case NL80211_IFTYPE_P2P_GO:
7549 		/* ignore WME attributes if iface/sta is not capable */
7550 		if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) ||
7551 		    !(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)))
7552 			params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
7553 
7554 		/* TDLS peers cannot be added */
7555 		if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
7556 		    info->attrs[NL80211_ATTR_PEER_AID])
7557 			return -EINVAL;
7558 		/* but don't bother the driver with it */
7559 		params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
7560 
7561 		/* allow authenticated/associated only if driver handles it */
7562 		if (!(rdev->wiphy.features &
7563 				NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
7564 		    params.sta_flags_mask & auth_assoc)
7565 			return -EINVAL;
7566 
7567 		/* Older userspace, or userspace wanting to be compatible with
7568 		 * !NL80211_FEATURE_FULL_AP_CLIENT_STATE, will not set the auth
7569 		 * and assoc flags in the mask, but assumes the station will be
7570 		 * added as associated anyway since this was the required driver
7571 		 * behaviour before NL80211_FEATURE_FULL_AP_CLIENT_STATE was
7572 		 * introduced.
7573 		 * In order to not bother drivers with this quirk in the API
7574 		 * set the flags in both the mask and set for new stations in
7575 		 * this case.
7576 		 */
7577 		if (!(params.sta_flags_mask & auth_assoc)) {
7578 			params.sta_flags_mask |= auth_assoc;
7579 			params.sta_flags_set |= auth_assoc;
7580 		}
7581 
7582 		/* must be last in here for error handling */
7583 		params.vlan = get_vlan(info, rdev);
7584 		if (IS_ERR(params.vlan))
7585 			return PTR_ERR(params.vlan);
7586 		break;
7587 	case NL80211_IFTYPE_MESH_POINT:
7588 		/* ignore uAPSD data */
7589 		params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
7590 
7591 		/* associated is disallowed */
7592 		if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
7593 			return -EINVAL;
7594 		/* TDLS peers cannot be added */
7595 		if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
7596 		    info->attrs[NL80211_ATTR_PEER_AID])
7597 			return -EINVAL;
7598 		break;
7599 	case NL80211_IFTYPE_STATION:
7600 	case NL80211_IFTYPE_P2P_CLIENT:
7601 		/* ignore uAPSD data */
7602 		params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
7603 
7604 		/* these are disallowed */
7605 		if (params.sta_flags_mask &
7606 				(BIT(NL80211_STA_FLAG_ASSOCIATED) |
7607 				 BIT(NL80211_STA_FLAG_AUTHENTICATED)))
7608 			return -EINVAL;
7609 		/* Only TDLS peers can be added */
7610 		if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
7611 			return -EINVAL;
7612 		/* Can only add if TDLS ... */
7613 		if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
7614 			return -EOPNOTSUPP;
7615 		/* ... with external setup is supported */
7616 		if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
7617 			return -EOPNOTSUPP;
7618 		/*
7619 		 * Older wpa_supplicant versions always mark the TDLS peer
7620 		 * as authorized, but it shouldn't yet be.
7621 		 */
7622 		params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_AUTHORIZED);
7623 		break;
7624 	default:
7625 		return -EOPNOTSUPP;
7626 	}
7627 
7628 	/* be aware of params.vlan when changing code here */
7629 
7630 	wdev_lock(dev->ieee80211_ptr);
7631 	if (wdev->valid_links) {
7632 		if (params.link_sta_params.link_id < 0) {
7633 			err = -EINVAL;
7634 			goto out;
7635 		}
7636 		if (!(wdev->valid_links & BIT(params.link_sta_params.link_id))) {
7637 			err = -ENOLINK;
7638 			goto out;
7639 		}
7640 	} else {
7641 		if (params.link_sta_params.link_id >= 0) {
7642 			err = -EINVAL;
7643 			goto out;
7644 		}
7645 	}
7646 	err = rdev_add_station(rdev, dev, mac_addr, &params);
7647 out:
7648 	wdev_unlock(dev->ieee80211_ptr);
7649 	dev_put(params.vlan);
7650 	return err;
7651 }
7652 
nl80211_del_station(struct sk_buff * skb,struct genl_info * info)7653 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
7654 {
7655 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
7656 	struct net_device *dev = info->user_ptr[1];
7657 	struct station_del_parameters params;
7658 	int ret;
7659 
7660 	memset(&params, 0, sizeof(params));
7661 
7662 	if (info->attrs[NL80211_ATTR_MAC])
7663 		params.mac = nla_data(info->attrs[NL80211_ATTR_MAC]);
7664 
7665 	switch (dev->ieee80211_ptr->iftype) {
7666 	case NL80211_IFTYPE_AP:
7667 	case NL80211_IFTYPE_AP_VLAN:
7668 	case NL80211_IFTYPE_MESH_POINT:
7669 	case NL80211_IFTYPE_P2P_GO:
7670 		/* always accept these */
7671 		break;
7672 	case NL80211_IFTYPE_ADHOC:
7673 		/* conditionally accept */
7674 		if (wiphy_ext_feature_isset(&rdev->wiphy,
7675 					    NL80211_EXT_FEATURE_DEL_IBSS_STA))
7676 			break;
7677 		return -EINVAL;
7678 	default:
7679 		return -EINVAL;
7680 	}
7681 
7682 	if (!rdev->ops->del_station)
7683 		return -EOPNOTSUPP;
7684 
7685 	if (info->attrs[NL80211_ATTR_MGMT_SUBTYPE]) {
7686 		params.subtype =
7687 			nla_get_u8(info->attrs[NL80211_ATTR_MGMT_SUBTYPE]);
7688 		if (params.subtype != IEEE80211_STYPE_DISASSOC >> 4 &&
7689 		    params.subtype != IEEE80211_STYPE_DEAUTH >> 4)
7690 			return -EINVAL;
7691 	} else {
7692 		/* Default to Deauthentication frame */
7693 		params.subtype = IEEE80211_STYPE_DEAUTH >> 4;
7694 	}
7695 
7696 	if (info->attrs[NL80211_ATTR_REASON_CODE]) {
7697 		params.reason_code =
7698 			nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
7699 		if (params.reason_code == 0)
7700 			return -EINVAL; /* 0 is reserved */
7701 	} else {
7702 		/* Default to reason code 2 */
7703 		params.reason_code = WLAN_REASON_PREV_AUTH_NOT_VALID;
7704 	}
7705 
7706 	wdev_lock(dev->ieee80211_ptr);
7707 	ret = rdev_del_station(rdev, dev, &params);
7708 	wdev_unlock(dev->ieee80211_ptr);
7709 
7710 	return ret;
7711 }
7712 
nl80211_send_mpath(struct sk_buff * msg,u32 portid,u32 seq,int flags,struct net_device * dev,u8 * dst,u8 * next_hop,struct mpath_info * pinfo)7713 static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
7714 				int flags, struct net_device *dev,
7715 				u8 *dst, u8 *next_hop,
7716 				struct mpath_info *pinfo)
7717 {
7718 	void *hdr;
7719 	struct nlattr *pinfoattr;
7720 
7721 	hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_MPATH);
7722 	if (!hdr)
7723 		return -1;
7724 
7725 	if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
7726 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
7727 	    nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
7728 	    nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
7729 		goto nla_put_failure;
7730 
7731 	pinfoattr = nla_nest_start_noflag(msg, NL80211_ATTR_MPATH_INFO);
7732 	if (!pinfoattr)
7733 		goto nla_put_failure;
7734 	if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
7735 	    nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
7736 			pinfo->frame_qlen))
7737 		goto nla_put_failure;
7738 	if (((pinfo->filled & MPATH_INFO_SN) &&
7739 	     nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
7740 	    ((pinfo->filled & MPATH_INFO_METRIC) &&
7741 	     nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
7742 			 pinfo->metric)) ||
7743 	    ((pinfo->filled & MPATH_INFO_EXPTIME) &&
7744 	     nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
7745 			 pinfo->exptime)) ||
7746 	    ((pinfo->filled & MPATH_INFO_FLAGS) &&
7747 	     nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
7748 			pinfo->flags)) ||
7749 	    ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
7750 	     nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
7751 			 pinfo->discovery_timeout)) ||
7752 	    ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
7753 	     nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
7754 			pinfo->discovery_retries)) ||
7755 	    ((pinfo->filled & MPATH_INFO_HOP_COUNT) &&
7756 	     nla_put_u8(msg, NL80211_MPATH_INFO_HOP_COUNT,
7757 			pinfo->hop_count)) ||
7758 	    ((pinfo->filled & MPATH_INFO_PATH_CHANGE) &&
7759 	     nla_put_u32(msg, NL80211_MPATH_INFO_PATH_CHANGE,
7760 			 pinfo->path_change_count)))
7761 		goto nla_put_failure;
7762 
7763 	nla_nest_end(msg, pinfoattr);
7764 
7765 	genlmsg_end(msg, hdr);
7766 	return 0;
7767 
7768  nla_put_failure:
7769 	genlmsg_cancel(msg, hdr);
7770 	return -EMSGSIZE;
7771 }
7772 
nl80211_dump_mpath(struct sk_buff * skb,struct netlink_callback * cb)7773 static int nl80211_dump_mpath(struct sk_buff *skb,
7774 			      struct netlink_callback *cb)
7775 {
7776 	struct mpath_info pinfo;
7777 	struct cfg80211_registered_device *rdev;
7778 	struct wireless_dev *wdev;
7779 	u8 dst[ETH_ALEN];
7780 	u8 next_hop[ETH_ALEN];
7781 	int path_idx = cb->args[2];
7782 	int err;
7783 
7784 	err = nl80211_prepare_wdev_dump(cb, &rdev, &wdev, NULL);
7785 	if (err)
7786 		return err;
7787 	/* nl80211_prepare_wdev_dump acquired it in the successful case */
7788 	__acquire(&rdev->wiphy.mtx);
7789 
7790 	if (!rdev->ops->dump_mpath) {
7791 		err = -EOPNOTSUPP;
7792 		goto out_err;
7793 	}
7794 
7795 	if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
7796 		err = -EOPNOTSUPP;
7797 		goto out_err;
7798 	}
7799 
7800 	while (1) {
7801 		err = rdev_dump_mpath(rdev, wdev->netdev, path_idx, dst,
7802 				      next_hop, &pinfo);
7803 		if (err == -ENOENT)
7804 			break;
7805 		if (err)
7806 			goto out_err;
7807 
7808 		if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
7809 				       cb->nlh->nlmsg_seq, NLM_F_MULTI,
7810 				       wdev->netdev, dst, next_hop,
7811 				       &pinfo) < 0)
7812 			goto out;
7813 
7814 		path_idx++;
7815 	}
7816 
7817  out:
7818 	cb->args[2] = path_idx;
7819 	err = skb->len;
7820  out_err:
7821 	wiphy_unlock(&rdev->wiphy);
7822 	return err;
7823 }
7824 
nl80211_get_mpath(struct sk_buff * skb,struct genl_info * info)7825 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
7826 {
7827 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
7828 	int err;
7829 	struct net_device *dev = info->user_ptr[1];
7830 	struct mpath_info pinfo;
7831 	struct sk_buff *msg;
7832 	u8 *dst = NULL;
7833 	u8 next_hop[ETH_ALEN];
7834 
7835 	memset(&pinfo, 0, sizeof(pinfo));
7836 
7837 	if (!info->attrs[NL80211_ATTR_MAC])
7838 		return -EINVAL;
7839 
7840 	dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
7841 
7842 	if (!rdev->ops->get_mpath)
7843 		return -EOPNOTSUPP;
7844 
7845 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
7846 		return -EOPNOTSUPP;
7847 
7848 	err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
7849 	if (err)
7850 		return err;
7851 
7852 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7853 	if (!msg)
7854 		return -ENOMEM;
7855 
7856 	if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
7857 				 dev, dst, next_hop, &pinfo) < 0) {
7858 		nlmsg_free(msg);
7859 		return -ENOBUFS;
7860 	}
7861 
7862 	return genlmsg_reply(msg, info);
7863 }
7864 
nl80211_set_mpath(struct sk_buff * skb,struct genl_info * info)7865 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
7866 {
7867 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
7868 	struct net_device *dev = info->user_ptr[1];
7869 	u8 *dst = NULL;
7870 	u8 *next_hop = NULL;
7871 
7872 	if (!info->attrs[NL80211_ATTR_MAC])
7873 		return -EINVAL;
7874 
7875 	if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
7876 		return -EINVAL;
7877 
7878 	dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
7879 	next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
7880 
7881 	if (!rdev->ops->change_mpath)
7882 		return -EOPNOTSUPP;
7883 
7884 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
7885 		return -EOPNOTSUPP;
7886 
7887 	return rdev_change_mpath(rdev, dev, dst, next_hop);
7888 }
7889 
nl80211_new_mpath(struct sk_buff * skb,struct genl_info * info)7890 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
7891 {
7892 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
7893 	struct net_device *dev = info->user_ptr[1];
7894 	u8 *dst = NULL;
7895 	u8 *next_hop = NULL;
7896 
7897 	if (!info->attrs[NL80211_ATTR_MAC])
7898 		return -EINVAL;
7899 
7900 	if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
7901 		return -EINVAL;
7902 
7903 	dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
7904 	next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
7905 
7906 	if (!rdev->ops->add_mpath)
7907 		return -EOPNOTSUPP;
7908 
7909 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
7910 		return -EOPNOTSUPP;
7911 
7912 	return rdev_add_mpath(rdev, dev, dst, next_hop);
7913 }
7914 
nl80211_del_mpath(struct sk_buff * skb,struct genl_info * info)7915 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
7916 {
7917 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
7918 	struct net_device *dev = info->user_ptr[1];
7919 	u8 *dst = NULL;
7920 
7921 	if (info->attrs[NL80211_ATTR_MAC])
7922 		dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
7923 
7924 	if (!rdev->ops->del_mpath)
7925 		return -EOPNOTSUPP;
7926 
7927 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
7928 		return -EOPNOTSUPP;
7929 
7930 	return rdev_del_mpath(rdev, dev, dst);
7931 }
7932 
nl80211_get_mpp(struct sk_buff * skb,struct genl_info * info)7933 static int nl80211_get_mpp(struct sk_buff *skb, struct genl_info *info)
7934 {
7935 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
7936 	int err;
7937 	struct net_device *dev = info->user_ptr[1];
7938 	struct mpath_info pinfo;
7939 	struct sk_buff *msg;
7940 	u8 *dst = NULL;
7941 	u8 mpp[ETH_ALEN];
7942 
7943 	memset(&pinfo, 0, sizeof(pinfo));
7944 
7945 	if (!info->attrs[NL80211_ATTR_MAC])
7946 		return -EINVAL;
7947 
7948 	dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
7949 
7950 	if (!rdev->ops->get_mpp)
7951 		return -EOPNOTSUPP;
7952 
7953 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
7954 		return -EOPNOTSUPP;
7955 
7956 	err = rdev_get_mpp(rdev, dev, dst, mpp, &pinfo);
7957 	if (err)
7958 		return err;
7959 
7960 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7961 	if (!msg)
7962 		return -ENOMEM;
7963 
7964 	if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
7965 			       dev, dst, mpp, &pinfo) < 0) {
7966 		nlmsg_free(msg);
7967 		return -ENOBUFS;
7968 	}
7969 
7970 	return genlmsg_reply(msg, info);
7971 }
7972 
nl80211_dump_mpp(struct sk_buff * skb,struct netlink_callback * cb)7973 static int nl80211_dump_mpp(struct sk_buff *skb,
7974 			    struct netlink_callback *cb)
7975 {
7976 	struct mpath_info pinfo;
7977 	struct cfg80211_registered_device *rdev;
7978 	struct wireless_dev *wdev;
7979 	u8 dst[ETH_ALEN];
7980 	u8 mpp[ETH_ALEN];
7981 	int path_idx = cb->args[2];
7982 	int err;
7983 
7984 	err = nl80211_prepare_wdev_dump(cb, &rdev, &wdev, NULL);
7985 	if (err)
7986 		return err;
7987 	/* nl80211_prepare_wdev_dump acquired it in the successful case */
7988 	__acquire(&rdev->wiphy.mtx);
7989 
7990 	if (!rdev->ops->dump_mpp) {
7991 		err = -EOPNOTSUPP;
7992 		goto out_err;
7993 	}
7994 
7995 	if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
7996 		err = -EOPNOTSUPP;
7997 		goto out_err;
7998 	}
7999 
8000 	while (1) {
8001 		err = rdev_dump_mpp(rdev, wdev->netdev, path_idx, dst,
8002 				    mpp, &pinfo);
8003 		if (err == -ENOENT)
8004 			break;
8005 		if (err)
8006 			goto out_err;
8007 
8008 		if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
8009 				       cb->nlh->nlmsg_seq, NLM_F_MULTI,
8010 				       wdev->netdev, dst, mpp,
8011 				       &pinfo) < 0)
8012 			goto out;
8013 
8014 		path_idx++;
8015 	}
8016 
8017  out:
8018 	cb->args[2] = path_idx;
8019 	err = skb->len;
8020  out_err:
8021 	wiphy_unlock(&rdev->wiphy);
8022 	return err;
8023 }
8024 
nl80211_set_bss(struct sk_buff * skb,struct genl_info * info)8025 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
8026 {
8027 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
8028 	struct net_device *dev = info->user_ptr[1];
8029 	struct wireless_dev *wdev = dev->ieee80211_ptr;
8030 	struct bss_parameters params;
8031 	int err;
8032 
8033 	memset(&params, 0, sizeof(params));
8034 	params.link_id = nl80211_link_id_or_invalid(info->attrs);
8035 	/* default to not changing parameters */
8036 	params.use_cts_prot = -1;
8037 	params.use_short_preamble = -1;
8038 	params.use_short_slot_time = -1;
8039 	params.ap_isolate = -1;
8040 	params.ht_opmode = -1;
8041 	params.p2p_ctwindow = -1;
8042 	params.p2p_opp_ps = -1;
8043 
8044 	if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
8045 		params.use_cts_prot =
8046 		    nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
8047 	if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
8048 		params.use_short_preamble =
8049 		    nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
8050 	if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
8051 		params.use_short_slot_time =
8052 		    nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
8053 	if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
8054 		params.basic_rates =
8055 			nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
8056 		params.basic_rates_len =
8057 			nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
8058 	}
8059 	if (info->attrs[NL80211_ATTR_AP_ISOLATE])
8060 		params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
8061 	if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
8062 		params.ht_opmode =
8063 			nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
8064 
8065 	if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
8066 		if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
8067 			return -EINVAL;
8068 		params.p2p_ctwindow =
8069 			nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
8070 		if (params.p2p_ctwindow != 0 &&
8071 		    !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
8072 			return -EINVAL;
8073 	}
8074 
8075 	if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
8076 		u8 tmp;
8077 
8078 		if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
8079 			return -EINVAL;
8080 		tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
8081 		params.p2p_opp_ps = tmp;
8082 		if (params.p2p_opp_ps &&
8083 		    !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
8084 			return -EINVAL;
8085 	}
8086 
8087 	if (!rdev->ops->change_bss)
8088 		return -EOPNOTSUPP;
8089 
8090 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
8091 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
8092 		return -EOPNOTSUPP;
8093 
8094 	wdev_lock(wdev);
8095 	err = rdev_change_bss(rdev, dev, &params);
8096 	wdev_unlock(wdev);
8097 
8098 	return err;
8099 }
8100 
nl80211_req_set_reg(struct sk_buff * skb,struct genl_info * info)8101 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
8102 {
8103 	char *data = NULL;
8104 	bool is_indoor;
8105 	enum nl80211_user_reg_hint_type user_reg_hint_type;
8106 	u32 owner_nlportid;
8107 
8108 	/*
8109 	 * You should only get this when cfg80211 hasn't yet initialized
8110 	 * completely when built-in to the kernel right between the time
8111 	 * window between nl80211_init() and regulatory_init(), if that is
8112 	 * even possible.
8113 	 */
8114 	if (unlikely(!rcu_access_pointer(cfg80211_regdomain)))
8115 		return -EINPROGRESS;
8116 
8117 	if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
8118 		user_reg_hint_type =
8119 		  nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
8120 	else
8121 		user_reg_hint_type = NL80211_USER_REG_HINT_USER;
8122 
8123 	switch (user_reg_hint_type) {
8124 	case NL80211_USER_REG_HINT_USER:
8125 	case NL80211_USER_REG_HINT_CELL_BASE:
8126 		if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
8127 			return -EINVAL;
8128 
8129 		data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
8130 		return regulatory_hint_user(data, user_reg_hint_type);
8131 	case NL80211_USER_REG_HINT_INDOOR:
8132 		if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
8133 			owner_nlportid = info->snd_portid;
8134 			is_indoor = !!info->attrs[NL80211_ATTR_REG_INDOOR];
8135 		} else {
8136 			owner_nlportid = 0;
8137 			is_indoor = true;
8138 		}
8139 
8140 		return regulatory_hint_indoor(is_indoor, owner_nlportid);
8141 	default:
8142 		return -EINVAL;
8143 	}
8144 }
8145 
nl80211_reload_regdb(struct sk_buff * skb,struct genl_info * info)8146 static int nl80211_reload_regdb(struct sk_buff *skb, struct genl_info *info)
8147 {
8148 	return reg_reload_regdb();
8149 }
8150 
nl80211_get_mesh_config(struct sk_buff * skb,struct genl_info * info)8151 static int nl80211_get_mesh_config(struct sk_buff *skb,
8152 				   struct genl_info *info)
8153 {
8154 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
8155 	struct net_device *dev = info->user_ptr[1];
8156 	struct wireless_dev *wdev = dev->ieee80211_ptr;
8157 	struct mesh_config cur_params;
8158 	int err = 0;
8159 	void *hdr;
8160 	struct nlattr *pinfoattr;
8161 	struct sk_buff *msg;
8162 
8163 	if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
8164 		return -EOPNOTSUPP;
8165 
8166 	if (!rdev->ops->get_mesh_config)
8167 		return -EOPNOTSUPP;
8168 
8169 	wdev_lock(wdev);
8170 	/* If not connected, get default parameters */
8171 	if (!wdev->u.mesh.id_len)
8172 		memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
8173 	else
8174 		err = rdev_get_mesh_config(rdev, dev, &cur_params);
8175 	wdev_unlock(wdev);
8176 
8177 	if (err)
8178 		return err;
8179 
8180 	/* Draw up a netlink message to send back */
8181 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8182 	if (!msg)
8183 		return -ENOMEM;
8184 	hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
8185 			     NL80211_CMD_GET_MESH_CONFIG);
8186 	if (!hdr)
8187 		goto out;
8188 	pinfoattr = nla_nest_start_noflag(msg, NL80211_ATTR_MESH_CONFIG);
8189 	if (!pinfoattr)
8190 		goto nla_put_failure;
8191 	if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8192 	    nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
8193 			cur_params.dot11MeshRetryTimeout) ||
8194 	    nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
8195 			cur_params.dot11MeshConfirmTimeout) ||
8196 	    nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
8197 			cur_params.dot11MeshHoldingTimeout) ||
8198 	    nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
8199 			cur_params.dot11MeshMaxPeerLinks) ||
8200 	    nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
8201 		       cur_params.dot11MeshMaxRetries) ||
8202 	    nla_put_u8(msg, NL80211_MESHCONF_TTL,
8203 		       cur_params.dot11MeshTTL) ||
8204 	    nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
8205 		       cur_params.element_ttl) ||
8206 	    nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
8207 		       cur_params.auto_open_plinks) ||
8208 	    nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
8209 			cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
8210 	    nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
8211 		       cur_params.dot11MeshHWMPmaxPREQretries) ||
8212 	    nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
8213 			cur_params.path_refresh_time) ||
8214 	    nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
8215 			cur_params.min_discovery_timeout) ||
8216 	    nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
8217 			cur_params.dot11MeshHWMPactivePathTimeout) ||
8218 	    nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
8219 			cur_params.dot11MeshHWMPpreqMinInterval) ||
8220 	    nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
8221 			cur_params.dot11MeshHWMPperrMinInterval) ||
8222 	    nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
8223 			cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
8224 	    nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
8225 		       cur_params.dot11MeshHWMPRootMode) ||
8226 	    nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
8227 			cur_params.dot11MeshHWMPRannInterval) ||
8228 	    nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
8229 		       cur_params.dot11MeshGateAnnouncementProtocol) ||
8230 	    nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
8231 		       cur_params.dot11MeshForwarding) ||
8232 	    nla_put_s32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
8233 			cur_params.rssi_threshold) ||
8234 	    nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
8235 			cur_params.ht_opmode) ||
8236 	    nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
8237 			cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
8238 	    nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
8239 			cur_params.dot11MeshHWMProotInterval) ||
8240 	    nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
8241 			cur_params.dot11MeshHWMPconfirmationInterval) ||
8242 	    nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE,
8243 			cur_params.power_mode) ||
8244 	    nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW,
8245 			cur_params.dot11MeshAwakeWindowDuration) ||
8246 	    nla_put_u32(msg, NL80211_MESHCONF_PLINK_TIMEOUT,
8247 			cur_params.plink_timeout) ||
8248 	    nla_put_u8(msg, NL80211_MESHCONF_CONNECTED_TO_GATE,
8249 		       cur_params.dot11MeshConnectedToMeshGate) ||
8250 	    nla_put_u8(msg, NL80211_MESHCONF_NOLEARN,
8251 		       cur_params.dot11MeshNolearn) ||
8252 	    nla_put_u8(msg, NL80211_MESHCONF_CONNECTED_TO_AS,
8253 		       cur_params.dot11MeshConnectedToAuthServer))
8254 		goto nla_put_failure;
8255 	nla_nest_end(msg, pinfoattr);
8256 	genlmsg_end(msg, hdr);
8257 	return genlmsg_reply(msg, info);
8258 
8259  nla_put_failure:
8260  out:
8261 	nlmsg_free(msg);
8262 	return -ENOBUFS;
8263 }
8264 
8265 static const struct nla_policy
8266 nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
8267 	[NL80211_MESHCONF_RETRY_TIMEOUT] =
8268 		NLA_POLICY_RANGE(NLA_U16, 1, 255),
8269 	[NL80211_MESHCONF_CONFIRM_TIMEOUT] =
8270 		NLA_POLICY_RANGE(NLA_U16, 1, 255),
8271 	[NL80211_MESHCONF_HOLDING_TIMEOUT] =
8272 		NLA_POLICY_RANGE(NLA_U16, 1, 255),
8273 	[NL80211_MESHCONF_MAX_PEER_LINKS] =
8274 		NLA_POLICY_RANGE(NLA_U16, 0, 255),
8275 	[NL80211_MESHCONF_MAX_RETRIES] = NLA_POLICY_MAX(NLA_U8, 16),
8276 	[NL80211_MESHCONF_TTL] = NLA_POLICY_MIN(NLA_U8, 1),
8277 	[NL80211_MESHCONF_ELEMENT_TTL] = NLA_POLICY_MIN(NLA_U8, 1),
8278 	[NL80211_MESHCONF_AUTO_OPEN_PLINKS] = NLA_POLICY_MAX(NLA_U8, 1),
8279 	[NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] =
8280 		NLA_POLICY_RANGE(NLA_U32, 1, 255),
8281 	[NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
8282 	[NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
8283 	[NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = NLA_POLICY_MIN(NLA_U16, 1),
8284 	[NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
8285 	[NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] =
8286 		NLA_POLICY_MIN(NLA_U16, 1),
8287 	[NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] =
8288 		NLA_POLICY_MIN(NLA_U16, 1),
8289 	[NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] =
8290 		NLA_POLICY_MIN(NLA_U16, 1),
8291 	[NL80211_MESHCONF_HWMP_ROOTMODE] = NLA_POLICY_MAX(NLA_U8, 4),
8292 	[NL80211_MESHCONF_HWMP_RANN_INTERVAL] =
8293 		NLA_POLICY_MIN(NLA_U16, 1),
8294 	[NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = NLA_POLICY_MAX(NLA_U8, 1),
8295 	[NL80211_MESHCONF_FORWARDING] = NLA_POLICY_MAX(NLA_U8, 1),
8296 	[NL80211_MESHCONF_RSSI_THRESHOLD] =
8297 		NLA_POLICY_RANGE(NLA_S32, -255, 0),
8298 	[NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
8299 	[NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
8300 	[NL80211_MESHCONF_HWMP_ROOT_INTERVAL] =
8301 		NLA_POLICY_MIN(NLA_U16, 1),
8302 	[NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] =
8303 		NLA_POLICY_MIN(NLA_U16, 1),
8304 	[NL80211_MESHCONF_POWER_MODE] =
8305 		NLA_POLICY_RANGE(NLA_U32,
8306 				 NL80211_MESH_POWER_ACTIVE,
8307 				 NL80211_MESH_POWER_MAX),
8308 	[NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 },
8309 	[NL80211_MESHCONF_PLINK_TIMEOUT] = { .type = NLA_U32 },
8310 	[NL80211_MESHCONF_CONNECTED_TO_GATE] = NLA_POLICY_RANGE(NLA_U8, 0, 1),
8311 	[NL80211_MESHCONF_NOLEARN] = NLA_POLICY_RANGE(NLA_U8, 0, 1),
8312 	[NL80211_MESHCONF_CONNECTED_TO_AS] = NLA_POLICY_RANGE(NLA_U8, 0, 1),
8313 };
8314 
8315 static const struct nla_policy
8316 	nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
8317 	[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
8318 	[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
8319 	[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
8320 	[NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
8321 	[NL80211_MESH_SETUP_AUTH_PROTOCOL] = { .type = NLA_U8 },
8322 	[NL80211_MESH_SETUP_USERSPACE_MPM] = { .type = NLA_FLAG },
8323 	[NL80211_MESH_SETUP_IE] =
8324 		NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_ie_attr,
8325 				       IEEE80211_MAX_DATA_LEN),
8326 	[NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
8327 };
8328 
nl80211_parse_mesh_config(struct genl_info * info,struct mesh_config * cfg,u32 * mask_out)8329 static int nl80211_parse_mesh_config(struct genl_info *info,
8330 				     struct mesh_config *cfg,
8331 				     u32 *mask_out)
8332 {
8333 	struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
8334 	u32 mask = 0;
8335 	u16 ht_opmode;
8336 
8337 #define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, mask, attr, fn)	\
8338 do {									\
8339 	if (tb[attr]) {							\
8340 		cfg->param = fn(tb[attr]);				\
8341 		mask |= BIT((attr) - 1);				\
8342 	}								\
8343 } while (0)
8344 
8345 	if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
8346 		return -EINVAL;
8347 	if (nla_parse_nested_deprecated(tb, NL80211_MESHCONF_ATTR_MAX, info->attrs[NL80211_ATTR_MESH_CONFIG], nl80211_meshconf_params_policy, info->extack))
8348 		return -EINVAL;
8349 
8350 	/* This makes sure that there aren't more than 32 mesh config
8351 	 * parameters (otherwise our bitfield scheme would not work.) */
8352 	BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
8353 
8354 	/* Fill in the params struct */
8355 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, mask,
8356 				  NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
8357 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, mask,
8358 				  NL80211_MESHCONF_CONFIRM_TIMEOUT,
8359 				  nla_get_u16);
8360 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, mask,
8361 				  NL80211_MESHCONF_HOLDING_TIMEOUT,
8362 				  nla_get_u16);
8363 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, mask,
8364 				  NL80211_MESHCONF_MAX_PEER_LINKS,
8365 				  nla_get_u16);
8366 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, mask,
8367 				  NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
8368 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, mask,
8369 				  NL80211_MESHCONF_TTL, nla_get_u8);
8370 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, mask,
8371 				  NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
8372 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, mask,
8373 				  NL80211_MESHCONF_AUTO_OPEN_PLINKS,
8374 				  nla_get_u8);
8375 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
8376 				  mask,
8377 				  NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
8378 				  nla_get_u32);
8379 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, mask,
8380 				  NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
8381 				  nla_get_u8);
8382 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, mask,
8383 				  NL80211_MESHCONF_PATH_REFRESH_TIME,
8384 				  nla_get_u32);
8385 	if (mask & BIT(NL80211_MESHCONF_PATH_REFRESH_TIME) &&
8386 	    (cfg->path_refresh_time < 1 || cfg->path_refresh_time > 65535))
8387 		return -EINVAL;
8388 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, mask,
8389 				  NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
8390 				  nla_get_u16);
8391 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
8392 				  mask,
8393 				  NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
8394 				  nla_get_u32);
8395 	if (mask & BIT(NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT) &&
8396 	    (cfg->dot11MeshHWMPactivePathTimeout < 1 ||
8397 	     cfg->dot11MeshHWMPactivePathTimeout > 65535))
8398 		return -EINVAL;
8399 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval, mask,
8400 				  NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
8401 				  nla_get_u16);
8402 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval, mask,
8403 				  NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
8404 				  nla_get_u16);
8405 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
8406 				  dot11MeshHWMPnetDiameterTraversalTime, mask,
8407 				  NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
8408 				  nla_get_u16);
8409 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, mask,
8410 				  NL80211_MESHCONF_HWMP_ROOTMODE, nla_get_u8);
8411 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, mask,
8412 				  NL80211_MESHCONF_HWMP_RANN_INTERVAL,
8413 				  nla_get_u16);
8414 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshGateAnnouncementProtocol,
8415 				  mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
8416 				  nla_get_u8);
8417 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, mask,
8418 				  NL80211_MESHCONF_FORWARDING, nla_get_u8);
8419 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, mask,
8420 				  NL80211_MESHCONF_RSSI_THRESHOLD,
8421 				  nla_get_s32);
8422 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConnectedToMeshGate, mask,
8423 				  NL80211_MESHCONF_CONNECTED_TO_GATE,
8424 				  nla_get_u8);
8425 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConnectedToAuthServer, mask,
8426 				  NL80211_MESHCONF_CONNECTED_TO_AS,
8427 				  nla_get_u8);
8428 	/*
8429 	 * Check HT operation mode based on
8430 	 * IEEE 802.11-2016 9.4.2.57 HT Operation element.
8431 	 */
8432 	if (tb[NL80211_MESHCONF_HT_OPMODE]) {
8433 		ht_opmode = nla_get_u16(tb[NL80211_MESHCONF_HT_OPMODE]);
8434 
8435 		if (ht_opmode & ~(IEEE80211_HT_OP_MODE_PROTECTION |
8436 				  IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT |
8437 				  IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT))
8438 			return -EINVAL;
8439 
8440 		/* NON_HT_STA bit is reserved, but some programs set it */
8441 		ht_opmode &= ~IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT;
8442 
8443 		cfg->ht_opmode = ht_opmode;
8444 		mask |= (1 << (NL80211_MESHCONF_HT_OPMODE - 1));
8445 	}
8446 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
8447 				  dot11MeshHWMPactivePathToRootTimeout, mask,
8448 				  NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
8449 				  nla_get_u32);
8450 	if (mask & BIT(NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT) &&
8451 	    (cfg->dot11MeshHWMPactivePathToRootTimeout < 1 ||
8452 	     cfg->dot11MeshHWMPactivePathToRootTimeout > 65535))
8453 		return -EINVAL;
8454 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, mask,
8455 				  NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
8456 				  nla_get_u16);
8457 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPconfirmationInterval,
8458 				  mask,
8459 				  NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
8460 				  nla_get_u16);
8461 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode, mask,
8462 				  NL80211_MESHCONF_POWER_MODE, nla_get_u32);
8463 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration, mask,
8464 				  NL80211_MESHCONF_AWAKE_WINDOW, nla_get_u16);
8465 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, plink_timeout, mask,
8466 				  NL80211_MESHCONF_PLINK_TIMEOUT, nla_get_u32);
8467 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNolearn, mask,
8468 				  NL80211_MESHCONF_NOLEARN, nla_get_u8);
8469 	if (mask_out)
8470 		*mask_out = mask;
8471 
8472 	return 0;
8473 
8474 #undef FILL_IN_MESH_PARAM_IF_SET
8475 }
8476 
nl80211_parse_mesh_setup(struct genl_info * info,struct mesh_setup * setup)8477 static int nl80211_parse_mesh_setup(struct genl_info *info,
8478 				     struct mesh_setup *setup)
8479 {
8480 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
8481 	struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
8482 
8483 	if (!info->attrs[NL80211_ATTR_MESH_SETUP])
8484 		return -EINVAL;
8485 	if (nla_parse_nested_deprecated(tb, NL80211_MESH_SETUP_ATTR_MAX, info->attrs[NL80211_ATTR_MESH_SETUP], nl80211_mesh_setup_params_policy, info->extack))
8486 		return -EINVAL;
8487 
8488 	if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
8489 		setup->sync_method =
8490 		(nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
8491 		 IEEE80211_SYNC_METHOD_VENDOR :
8492 		 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
8493 
8494 	if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
8495 		setup->path_sel_proto =
8496 		(nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
8497 		 IEEE80211_PATH_PROTOCOL_VENDOR :
8498 		 IEEE80211_PATH_PROTOCOL_HWMP;
8499 
8500 	if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
8501 		setup->path_metric =
8502 		(nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
8503 		 IEEE80211_PATH_METRIC_VENDOR :
8504 		 IEEE80211_PATH_METRIC_AIRTIME;
8505 
8506 	if (tb[NL80211_MESH_SETUP_IE]) {
8507 		struct nlattr *ieattr =
8508 			tb[NL80211_MESH_SETUP_IE];
8509 		setup->ie = nla_data(ieattr);
8510 		setup->ie_len = nla_len(ieattr);
8511 	}
8512 	if (tb[NL80211_MESH_SETUP_USERSPACE_MPM] &&
8513 	    !(rdev->wiphy.features & NL80211_FEATURE_USERSPACE_MPM))
8514 		return -EINVAL;
8515 	setup->user_mpm = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_MPM]);
8516 	setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
8517 	setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
8518 	if (setup->is_secure)
8519 		setup->user_mpm = true;
8520 
8521 	if (tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]) {
8522 		if (!setup->user_mpm)
8523 			return -EINVAL;
8524 		setup->auth_id =
8525 			nla_get_u8(tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]);
8526 	}
8527 
8528 	return 0;
8529 }
8530 
nl80211_update_mesh_config(struct sk_buff * skb,struct genl_info * info)8531 static int nl80211_update_mesh_config(struct sk_buff *skb,
8532 				      struct genl_info *info)
8533 {
8534 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
8535 	struct net_device *dev = info->user_ptr[1];
8536 	struct wireless_dev *wdev = dev->ieee80211_ptr;
8537 	struct mesh_config cfg = {};
8538 	u32 mask;
8539 	int err;
8540 
8541 	if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
8542 		return -EOPNOTSUPP;
8543 
8544 	if (!rdev->ops->update_mesh_config)
8545 		return -EOPNOTSUPP;
8546 
8547 	err = nl80211_parse_mesh_config(info, &cfg, &mask);
8548 	if (err)
8549 		return err;
8550 
8551 	wdev_lock(wdev);
8552 	if (!wdev->u.mesh.id_len)
8553 		err = -ENOLINK;
8554 
8555 	if (!err)
8556 		err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
8557 
8558 	wdev_unlock(wdev);
8559 
8560 	return err;
8561 }
8562 
nl80211_put_regdom(const struct ieee80211_regdomain * regdom,struct sk_buff * msg)8563 static int nl80211_put_regdom(const struct ieee80211_regdomain *regdom,
8564 			      struct sk_buff *msg)
8565 {
8566 	struct nlattr *nl_reg_rules;
8567 	unsigned int i;
8568 
8569 	if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) ||
8570 	    (regdom->dfs_region &&
8571 	     nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region)))
8572 		goto nla_put_failure;
8573 
8574 	nl_reg_rules = nla_nest_start_noflag(msg, NL80211_ATTR_REG_RULES);
8575 	if (!nl_reg_rules)
8576 		goto nla_put_failure;
8577 
8578 	for (i = 0; i < regdom->n_reg_rules; i++) {
8579 		struct nlattr *nl_reg_rule;
8580 		const struct ieee80211_reg_rule *reg_rule;
8581 		const struct ieee80211_freq_range *freq_range;
8582 		const struct ieee80211_power_rule *power_rule;
8583 		unsigned int max_bandwidth_khz;
8584 
8585 		reg_rule = &regdom->reg_rules[i];
8586 		freq_range = &reg_rule->freq_range;
8587 		power_rule = &reg_rule->power_rule;
8588 
8589 		nl_reg_rule = nla_nest_start_noflag(msg, i);
8590 		if (!nl_reg_rule)
8591 			goto nla_put_failure;
8592 
8593 		max_bandwidth_khz = freq_range->max_bandwidth_khz;
8594 		if (!max_bandwidth_khz)
8595 			max_bandwidth_khz = reg_get_max_bandwidth(regdom,
8596 								  reg_rule);
8597 
8598 		if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
8599 				reg_rule->flags) ||
8600 		    nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
8601 				freq_range->start_freq_khz) ||
8602 		    nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
8603 				freq_range->end_freq_khz) ||
8604 		    nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
8605 				max_bandwidth_khz) ||
8606 		    nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
8607 				power_rule->max_antenna_gain) ||
8608 		    nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
8609 				power_rule->max_eirp) ||
8610 		    nla_put_u32(msg, NL80211_ATTR_DFS_CAC_TIME,
8611 				reg_rule->dfs_cac_ms))
8612 			goto nla_put_failure;
8613 
8614 		nla_nest_end(msg, nl_reg_rule);
8615 	}
8616 
8617 	nla_nest_end(msg, nl_reg_rules);
8618 	return 0;
8619 
8620 nla_put_failure:
8621 	return -EMSGSIZE;
8622 }
8623 
nl80211_get_reg_do(struct sk_buff * skb,struct genl_info * info)8624 static int nl80211_get_reg_do(struct sk_buff *skb, struct genl_info *info)
8625 {
8626 	const struct ieee80211_regdomain *regdom = NULL;
8627 	struct cfg80211_registered_device *rdev;
8628 	struct wiphy *wiphy = NULL;
8629 	struct sk_buff *msg;
8630 	int err = -EMSGSIZE;
8631 	void *hdr;
8632 
8633 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8634 	if (!msg)
8635 		return -ENOBUFS;
8636 
8637 	hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
8638 			     NL80211_CMD_GET_REG);
8639 	if (!hdr)
8640 		goto put_failure;
8641 
8642 	rtnl_lock();
8643 
8644 	if (info->attrs[NL80211_ATTR_WIPHY]) {
8645 		bool self_managed;
8646 
8647 		rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
8648 		if (IS_ERR(rdev)) {
8649 			err = PTR_ERR(rdev);
8650 			goto nla_put_failure;
8651 		}
8652 
8653 		wiphy = &rdev->wiphy;
8654 		self_managed = wiphy->regulatory_flags &
8655 			       REGULATORY_WIPHY_SELF_MANAGED;
8656 
8657 		rcu_read_lock();
8658 
8659 		regdom = get_wiphy_regdom(wiphy);
8660 
8661 		/* a self-managed-reg device must have a private regdom */
8662 		if (WARN_ON(!regdom && self_managed)) {
8663 			err = -EINVAL;
8664 			goto nla_put_failure_rcu;
8665 		}
8666 
8667 		if (regdom &&
8668 		    nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
8669 			goto nla_put_failure_rcu;
8670 	} else {
8671 		rcu_read_lock();
8672 	}
8673 
8674 	if (!wiphy && reg_last_request_cell_base() &&
8675 	    nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
8676 			NL80211_USER_REG_HINT_CELL_BASE))
8677 		goto nla_put_failure_rcu;
8678 
8679 	if (!regdom)
8680 		regdom = rcu_dereference(cfg80211_regdomain);
8681 
8682 	if (nl80211_put_regdom(regdom, msg))
8683 		goto nla_put_failure_rcu;
8684 
8685 	rcu_read_unlock();
8686 
8687 	genlmsg_end(msg, hdr);
8688 	rtnl_unlock();
8689 	return genlmsg_reply(msg, info);
8690 
8691 nla_put_failure_rcu:
8692 	rcu_read_unlock();
8693 nla_put_failure:
8694 	rtnl_unlock();
8695 put_failure:
8696 	nlmsg_free(msg);
8697 	return err;
8698 }
8699 
nl80211_send_regdom(struct sk_buff * msg,struct netlink_callback * cb,u32 seq,int flags,struct wiphy * wiphy,const struct ieee80211_regdomain * regdom)8700 static int nl80211_send_regdom(struct sk_buff *msg, struct netlink_callback *cb,
8701 			       u32 seq, int flags, struct wiphy *wiphy,
8702 			       const struct ieee80211_regdomain *regdom)
8703 {
8704 	void *hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
8705 				   NL80211_CMD_GET_REG);
8706 
8707 	if (!hdr)
8708 		return -1;
8709 
8710 	genl_dump_check_consistent(cb, hdr);
8711 
8712 	if (nl80211_put_regdom(regdom, msg))
8713 		goto nla_put_failure;
8714 
8715 	if (!wiphy && reg_last_request_cell_base() &&
8716 	    nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
8717 			NL80211_USER_REG_HINT_CELL_BASE))
8718 		goto nla_put_failure;
8719 
8720 	if (wiphy &&
8721 	    nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
8722 		goto nla_put_failure;
8723 
8724 	if (wiphy && wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
8725 	    nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
8726 		goto nla_put_failure;
8727 
8728 	genlmsg_end(msg, hdr);
8729 	return 0;
8730 
8731 nla_put_failure:
8732 	genlmsg_cancel(msg, hdr);
8733 	return -EMSGSIZE;
8734 }
8735 
nl80211_get_reg_dump(struct sk_buff * skb,struct netlink_callback * cb)8736 static int nl80211_get_reg_dump(struct sk_buff *skb,
8737 				struct netlink_callback *cb)
8738 {
8739 	const struct ieee80211_regdomain *regdom = NULL;
8740 	struct cfg80211_registered_device *rdev;
8741 	int err, reg_idx, start = cb->args[2];
8742 
8743 	rcu_read_lock();
8744 
8745 	if (cfg80211_regdomain && start == 0) {
8746 		err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq,
8747 					  NLM_F_MULTI, NULL,
8748 					  rcu_dereference(cfg80211_regdomain));
8749 		if (err < 0)
8750 			goto out_err;
8751 	}
8752 
8753 	/* the global regdom is idx 0 */
8754 	reg_idx = 1;
8755 	list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
8756 		regdom = get_wiphy_regdom(&rdev->wiphy);
8757 		if (!regdom)
8758 			continue;
8759 
8760 		if (++reg_idx <= start)
8761 			continue;
8762 
8763 		err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq,
8764 					  NLM_F_MULTI, &rdev->wiphy, regdom);
8765 		if (err < 0) {
8766 			reg_idx--;
8767 			break;
8768 		}
8769 	}
8770 
8771 	cb->args[2] = reg_idx;
8772 	err = skb->len;
8773 out_err:
8774 	rcu_read_unlock();
8775 	return err;
8776 }
8777 
8778 #ifdef CONFIG_CFG80211_CRDA_SUPPORT
8779 static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
8780 	[NL80211_ATTR_REG_RULE_FLAGS]		= { .type = NLA_U32 },
8781 	[NL80211_ATTR_FREQ_RANGE_START]		= { .type = NLA_U32 },
8782 	[NL80211_ATTR_FREQ_RANGE_END]		= { .type = NLA_U32 },
8783 	[NL80211_ATTR_FREQ_RANGE_MAX_BW]	= { .type = NLA_U32 },
8784 	[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]	= { .type = NLA_U32 },
8785 	[NL80211_ATTR_POWER_RULE_MAX_EIRP]	= { .type = NLA_U32 },
8786 	[NL80211_ATTR_DFS_CAC_TIME]		= { .type = NLA_U32 },
8787 };
8788 
parse_reg_rule(struct nlattr * tb[],struct ieee80211_reg_rule * reg_rule)8789 static int parse_reg_rule(struct nlattr *tb[],
8790 	struct ieee80211_reg_rule *reg_rule)
8791 {
8792 	struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
8793 	struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
8794 
8795 	if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
8796 		return -EINVAL;
8797 	if (!tb[NL80211_ATTR_FREQ_RANGE_START])
8798 		return -EINVAL;
8799 	if (!tb[NL80211_ATTR_FREQ_RANGE_END])
8800 		return -EINVAL;
8801 	if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
8802 		return -EINVAL;
8803 	if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
8804 		return -EINVAL;
8805 
8806 	reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
8807 
8808 	freq_range->start_freq_khz =
8809 		nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
8810 	freq_range->end_freq_khz =
8811 		nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
8812 	freq_range->max_bandwidth_khz =
8813 		nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
8814 
8815 	power_rule->max_eirp =
8816 		nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
8817 
8818 	if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
8819 		power_rule->max_antenna_gain =
8820 			nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
8821 
8822 	if (tb[NL80211_ATTR_DFS_CAC_TIME])
8823 		reg_rule->dfs_cac_ms =
8824 			nla_get_u32(tb[NL80211_ATTR_DFS_CAC_TIME]);
8825 
8826 	return 0;
8827 }
8828 
nl80211_set_reg(struct sk_buff * skb,struct genl_info * info)8829 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
8830 {
8831 	struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
8832 	struct nlattr *nl_reg_rule;
8833 	char *alpha2;
8834 	int rem_reg_rules, r;
8835 	u32 num_rules = 0, rule_idx = 0;
8836 	enum nl80211_dfs_regions dfs_region = NL80211_DFS_UNSET;
8837 	struct ieee80211_regdomain *rd;
8838 
8839 	if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
8840 		return -EINVAL;
8841 
8842 	if (!info->attrs[NL80211_ATTR_REG_RULES])
8843 		return -EINVAL;
8844 
8845 	alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
8846 
8847 	if (info->attrs[NL80211_ATTR_DFS_REGION])
8848 		dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
8849 
8850 	nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
8851 			    rem_reg_rules) {
8852 		num_rules++;
8853 		if (num_rules > NL80211_MAX_SUPP_REG_RULES)
8854 			return -EINVAL;
8855 	}
8856 
8857 	rtnl_lock();
8858 	if (!reg_is_valid_request(alpha2)) {
8859 		r = -EINVAL;
8860 		goto out;
8861 	}
8862 
8863 	rd = kzalloc(struct_size(rd, reg_rules, num_rules), GFP_KERNEL);
8864 	if (!rd) {
8865 		r = -ENOMEM;
8866 		goto out;
8867 	}
8868 
8869 	rd->n_reg_rules = num_rules;
8870 	rd->alpha2[0] = alpha2[0];
8871 	rd->alpha2[1] = alpha2[1];
8872 
8873 	/*
8874 	 * Disable DFS master mode if the DFS region was
8875 	 * not supported or known on this kernel.
8876 	 */
8877 	if (reg_supported_dfs_region(dfs_region))
8878 		rd->dfs_region = dfs_region;
8879 
8880 	nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
8881 			    rem_reg_rules) {
8882 		r = nla_parse_nested_deprecated(tb, NL80211_REG_RULE_ATTR_MAX,
8883 						nl_reg_rule, reg_rule_policy,
8884 						info->extack);
8885 		if (r)
8886 			goto bad_reg;
8887 		r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
8888 		if (r)
8889 			goto bad_reg;
8890 
8891 		rule_idx++;
8892 
8893 		if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
8894 			r = -EINVAL;
8895 			goto bad_reg;
8896 		}
8897 	}
8898 
8899 	r = set_regdom(rd, REGD_SOURCE_CRDA);
8900 	/* set_regdom takes ownership of rd */
8901 	rd = NULL;
8902  bad_reg:
8903 	kfree(rd);
8904  out:
8905 	rtnl_unlock();
8906 	return r;
8907 }
8908 #endif /* CONFIG_CFG80211_CRDA_SUPPORT */
8909 
validate_scan_freqs(struct nlattr * freqs)8910 static int validate_scan_freqs(struct nlattr *freqs)
8911 {
8912 	struct nlattr *attr1, *attr2;
8913 	int n_channels = 0, tmp1, tmp2;
8914 
8915 	nla_for_each_nested(attr1, freqs, tmp1)
8916 		if (nla_len(attr1) != sizeof(u32))
8917 			return 0;
8918 
8919 	nla_for_each_nested(attr1, freqs, tmp1) {
8920 		n_channels++;
8921 		/*
8922 		 * Some hardware has a limited channel list for
8923 		 * scanning, and it is pretty much nonsensical
8924 		 * to scan for a channel twice, so disallow that
8925 		 * and don't require drivers to check that the
8926 		 * channel list they get isn't longer than what
8927 		 * they can scan, as long as they can scan all
8928 		 * the channels they registered at once.
8929 		 */
8930 		nla_for_each_nested(attr2, freqs, tmp2)
8931 			if (attr1 != attr2 &&
8932 			    nla_get_u32(attr1) == nla_get_u32(attr2))
8933 				return 0;
8934 	}
8935 
8936 	return n_channels;
8937 }
8938 
is_band_valid(struct wiphy * wiphy,enum nl80211_band b)8939 static bool is_band_valid(struct wiphy *wiphy, enum nl80211_band b)
8940 {
8941 	return b < NUM_NL80211_BANDS && wiphy->bands[b];
8942 }
8943 
parse_bss_select(struct nlattr * nla,struct wiphy * wiphy,struct cfg80211_bss_selection * bss_select)8944 static int parse_bss_select(struct nlattr *nla, struct wiphy *wiphy,
8945 			    struct cfg80211_bss_selection *bss_select)
8946 {
8947 	struct nlattr *attr[NL80211_BSS_SELECT_ATTR_MAX + 1];
8948 	struct nlattr *nest;
8949 	int err;
8950 	bool found = false;
8951 	int i;
8952 
8953 	/* only process one nested attribute */
8954 	nest = nla_data(nla);
8955 	if (!nla_ok(nest, nla_len(nest)))
8956 		return -EINVAL;
8957 
8958 	err = nla_parse_nested_deprecated(attr, NL80211_BSS_SELECT_ATTR_MAX,
8959 					  nest, nl80211_bss_select_policy,
8960 					  NULL);
8961 	if (err)
8962 		return err;
8963 
8964 	/* only one attribute may be given */
8965 	for (i = 0; i <= NL80211_BSS_SELECT_ATTR_MAX; i++) {
8966 		if (attr[i]) {
8967 			if (found)
8968 				return -EINVAL;
8969 			found = true;
8970 		}
8971 	}
8972 
8973 	bss_select->behaviour = __NL80211_BSS_SELECT_ATTR_INVALID;
8974 
8975 	if (attr[NL80211_BSS_SELECT_ATTR_RSSI])
8976 		bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI;
8977 
8978 	if (attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]) {
8979 		bss_select->behaviour = NL80211_BSS_SELECT_ATTR_BAND_PREF;
8980 		bss_select->param.band_pref =
8981 			nla_get_u32(attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]);
8982 		if (!is_band_valid(wiphy, bss_select->param.band_pref))
8983 			return -EINVAL;
8984 	}
8985 
8986 	if (attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]) {
8987 		struct nl80211_bss_select_rssi_adjust *adj_param;
8988 
8989 		adj_param = nla_data(attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]);
8990 		bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI_ADJUST;
8991 		bss_select->param.adjust.band = adj_param->band;
8992 		bss_select->param.adjust.delta = adj_param->delta;
8993 		if (!is_band_valid(wiphy, bss_select->param.adjust.band))
8994 			return -EINVAL;
8995 	}
8996 
8997 	/* user-space did not provide behaviour attribute */
8998 	if (bss_select->behaviour == __NL80211_BSS_SELECT_ATTR_INVALID)
8999 		return -EINVAL;
9000 
9001 	if (!(wiphy->bss_select_support & BIT(bss_select->behaviour)))
9002 		return -EINVAL;
9003 
9004 	return 0;
9005 }
9006 
nl80211_parse_random_mac(struct nlattr ** attrs,u8 * mac_addr,u8 * mac_addr_mask)9007 int nl80211_parse_random_mac(struct nlattr **attrs,
9008 			     u8 *mac_addr, u8 *mac_addr_mask)
9009 {
9010 	int i;
9011 
9012 	if (!attrs[NL80211_ATTR_MAC] && !attrs[NL80211_ATTR_MAC_MASK]) {
9013 		eth_zero_addr(mac_addr);
9014 		eth_zero_addr(mac_addr_mask);
9015 		mac_addr[0] = 0x2;
9016 		mac_addr_mask[0] = 0x3;
9017 
9018 		return 0;
9019 	}
9020 
9021 	/* need both or none */
9022 	if (!attrs[NL80211_ATTR_MAC] || !attrs[NL80211_ATTR_MAC_MASK])
9023 		return -EINVAL;
9024 
9025 	memcpy(mac_addr, nla_data(attrs[NL80211_ATTR_MAC]), ETH_ALEN);
9026 	memcpy(mac_addr_mask, nla_data(attrs[NL80211_ATTR_MAC_MASK]), ETH_ALEN);
9027 
9028 	/* don't allow or configure an mcast address */
9029 	if (!is_multicast_ether_addr(mac_addr_mask) ||
9030 	    is_multicast_ether_addr(mac_addr))
9031 		return -EINVAL;
9032 
9033 	/*
9034 	 * allow users to pass a MAC address that has bits set outside
9035 	 * of the mask, but don't bother drivers with having to deal
9036 	 * with such bits
9037 	 */
9038 	for (i = 0; i < ETH_ALEN; i++)
9039 		mac_addr[i] &= mac_addr_mask[i];
9040 
9041 	return 0;
9042 }
9043 
cfg80211_off_channel_oper_allowed(struct wireless_dev * wdev,struct ieee80211_channel * chan)9044 static bool cfg80211_off_channel_oper_allowed(struct wireless_dev *wdev,
9045 					      struct ieee80211_channel *chan)
9046 {
9047 	unsigned int link_id;
9048 	bool all_ok = true;
9049 
9050 	ASSERT_WDEV_LOCK(wdev);
9051 
9052 	if (!cfg80211_beaconing_iface_active(wdev))
9053 		return true;
9054 
9055 	/*
9056 	 * FIXME: check if we have a free HW resource/link for chan
9057 	 *
9058 	 * This, as well as the FIXME below, requires knowing the link
9059 	 * capabilities of the hardware.
9060 	 */
9061 
9062 	/* we cannot leave radar channels */
9063 	for_each_valid_link(wdev, link_id) {
9064 		struct cfg80211_chan_def *chandef;
9065 
9066 		chandef = wdev_chandef(wdev, link_id);
9067 		if (!chandef || !chandef->chan)
9068 			continue;
9069 
9070 		/*
9071 		 * FIXME: don't require all_ok, but rather check only the
9072 		 *	  correct HW resource/link onto which 'chan' falls,
9073 		 *	  as only that link leaves the channel for doing
9074 		 *	  the off-channel operation.
9075 		 */
9076 
9077 		if (chandef->chan->flags & IEEE80211_CHAN_RADAR)
9078 			all_ok = false;
9079 	}
9080 
9081 	if (all_ok)
9082 		return true;
9083 
9084 	return regulatory_pre_cac_allowed(wdev->wiphy);
9085 }
9086 
nl80211_check_scan_feat(struct wiphy * wiphy,u32 flags,u32 flag,enum nl80211_ext_feature_index feat)9087 static bool nl80211_check_scan_feat(struct wiphy *wiphy, u32 flags, u32 flag,
9088 				    enum nl80211_ext_feature_index feat)
9089 {
9090 	if (!(flags & flag))
9091 		return true;
9092 	if (wiphy_ext_feature_isset(wiphy, feat))
9093 		return true;
9094 	return false;
9095 }
9096 
9097 static int
nl80211_check_scan_flags(struct wiphy * wiphy,struct wireless_dev * wdev,void * request,struct nlattr ** attrs,bool is_sched_scan)9098 nl80211_check_scan_flags(struct wiphy *wiphy, struct wireless_dev *wdev,
9099 			 void *request, struct nlattr **attrs,
9100 			 bool is_sched_scan)
9101 {
9102 	u8 *mac_addr, *mac_addr_mask;
9103 	u32 *flags;
9104 	enum nl80211_feature_flags randomness_flag;
9105 
9106 	if (!attrs[NL80211_ATTR_SCAN_FLAGS])
9107 		return 0;
9108 
9109 	if (is_sched_scan) {
9110 		struct cfg80211_sched_scan_request *req = request;
9111 
9112 		randomness_flag = wdev ?
9113 				  NL80211_FEATURE_SCHED_SCAN_RANDOM_MAC_ADDR :
9114 				  NL80211_FEATURE_ND_RANDOM_MAC_ADDR;
9115 		flags = &req->flags;
9116 		mac_addr = req->mac_addr;
9117 		mac_addr_mask = req->mac_addr_mask;
9118 	} else {
9119 		struct cfg80211_scan_request *req = request;
9120 
9121 		randomness_flag = NL80211_FEATURE_SCAN_RANDOM_MAC_ADDR;
9122 		flags = &req->flags;
9123 		mac_addr = req->mac_addr;
9124 		mac_addr_mask = req->mac_addr_mask;
9125 	}
9126 
9127 	*flags = nla_get_u32(attrs[NL80211_ATTR_SCAN_FLAGS]);
9128 
9129 	if (((*flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
9130 	     !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
9131 	    !nl80211_check_scan_feat(wiphy, *flags,
9132 				     NL80211_SCAN_FLAG_LOW_SPAN,
9133 				     NL80211_EXT_FEATURE_LOW_SPAN_SCAN) ||
9134 	    !nl80211_check_scan_feat(wiphy, *flags,
9135 				     NL80211_SCAN_FLAG_LOW_POWER,
9136 				     NL80211_EXT_FEATURE_LOW_POWER_SCAN) ||
9137 	    !nl80211_check_scan_feat(wiphy, *flags,
9138 				     NL80211_SCAN_FLAG_HIGH_ACCURACY,
9139 				     NL80211_EXT_FEATURE_HIGH_ACCURACY_SCAN) ||
9140 	    !nl80211_check_scan_feat(wiphy, *flags,
9141 				     NL80211_SCAN_FLAG_FILS_MAX_CHANNEL_TIME,
9142 				     NL80211_EXT_FEATURE_FILS_MAX_CHANNEL_TIME) ||
9143 	    !nl80211_check_scan_feat(wiphy, *flags,
9144 				     NL80211_SCAN_FLAG_ACCEPT_BCAST_PROBE_RESP,
9145 				     NL80211_EXT_FEATURE_ACCEPT_BCAST_PROBE_RESP) ||
9146 	    !nl80211_check_scan_feat(wiphy, *flags,
9147 				     NL80211_SCAN_FLAG_OCE_PROBE_REQ_DEFERRAL_SUPPRESSION,
9148 				     NL80211_EXT_FEATURE_OCE_PROBE_REQ_DEFERRAL_SUPPRESSION) ||
9149 	    !nl80211_check_scan_feat(wiphy, *flags,
9150 				     NL80211_SCAN_FLAG_OCE_PROBE_REQ_HIGH_TX_RATE,
9151 				     NL80211_EXT_FEATURE_OCE_PROBE_REQ_HIGH_TX_RATE) ||
9152 	    !nl80211_check_scan_feat(wiphy, *flags,
9153 				     NL80211_SCAN_FLAG_RANDOM_SN,
9154 				     NL80211_EXT_FEATURE_SCAN_RANDOM_SN) ||
9155 	    !nl80211_check_scan_feat(wiphy, *flags,
9156 				     NL80211_SCAN_FLAG_MIN_PREQ_CONTENT,
9157 				     NL80211_EXT_FEATURE_SCAN_MIN_PREQ_CONTENT))
9158 		return -EOPNOTSUPP;
9159 
9160 	if (*flags & NL80211_SCAN_FLAG_RANDOM_ADDR) {
9161 		int err;
9162 
9163 		if (!(wiphy->features & randomness_flag) ||
9164 		    (wdev && wdev->connected))
9165 			return -EOPNOTSUPP;
9166 
9167 		err = nl80211_parse_random_mac(attrs, mac_addr, mac_addr_mask);
9168 		if (err)
9169 			return err;
9170 	}
9171 
9172 	return 0;
9173 }
9174 
nl80211_trigger_scan(struct sk_buff * skb,struct genl_info * info)9175 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
9176 {
9177 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
9178 	struct wireless_dev *wdev = info->user_ptr[1];
9179 	struct cfg80211_scan_request *request;
9180 	struct nlattr *scan_freqs = NULL;
9181 	bool scan_freqs_khz = false;
9182 	struct nlattr *attr;
9183 	struct wiphy *wiphy;
9184 	int err, tmp, n_ssids = 0, n_channels, i;
9185 	size_t ie_len, size;
9186 	size_t ssids_offset, ie_offset;
9187 
9188 	wiphy = &rdev->wiphy;
9189 
9190 	if (wdev->iftype == NL80211_IFTYPE_NAN)
9191 		return -EOPNOTSUPP;
9192 
9193 	if (!rdev->ops->scan)
9194 		return -EOPNOTSUPP;
9195 
9196 	if (rdev->scan_req || rdev->scan_msg)
9197 		return -EBUSY;
9198 
9199 	if (info->attrs[NL80211_ATTR_SCAN_FREQ_KHZ]) {
9200 		if (!wiphy_ext_feature_isset(wiphy,
9201 					     NL80211_EXT_FEATURE_SCAN_FREQ_KHZ))
9202 			return -EOPNOTSUPP;
9203 		scan_freqs = info->attrs[NL80211_ATTR_SCAN_FREQ_KHZ];
9204 		scan_freqs_khz = true;
9205 	} else if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES])
9206 		scan_freqs = info->attrs[NL80211_ATTR_SCAN_FREQUENCIES];
9207 
9208 	if (scan_freqs) {
9209 		n_channels = validate_scan_freqs(scan_freqs);
9210 		if (!n_channels)
9211 			return -EINVAL;
9212 	} else {
9213 		n_channels = ieee80211_get_num_supported_channels(wiphy);
9214 	}
9215 
9216 	if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
9217 		nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
9218 			n_ssids++;
9219 
9220 	if (n_ssids > wiphy->max_scan_ssids)
9221 		return -EINVAL;
9222 
9223 	if (info->attrs[NL80211_ATTR_IE])
9224 		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9225 	else
9226 		ie_len = 0;
9227 
9228 	if (ie_len > wiphy->max_scan_ie_len)
9229 		return -EINVAL;
9230 
9231 	size = struct_size(request, channels, n_channels);
9232 	ssids_offset = size;
9233 	size = size_add(size, array_size(sizeof(*request->ssids), n_ssids));
9234 	ie_offset = size;
9235 	size = size_add(size, ie_len);
9236 	request = kzalloc(size, GFP_KERNEL);
9237 	if (!request)
9238 		return -ENOMEM;
9239 	request->n_channels = n_channels;
9240 
9241 	if (n_ssids)
9242 		request->ssids = (void *)request + ssids_offset;
9243 	request->n_ssids = n_ssids;
9244 	if (ie_len)
9245 		request->ie = (void *)request + ie_offset;
9246 
9247 	i = 0;
9248 	if (scan_freqs) {
9249 		/* user specified, bail out if channel not found */
9250 		nla_for_each_nested(attr, scan_freqs, tmp) {
9251 			struct ieee80211_channel *chan;
9252 			int freq = nla_get_u32(attr);
9253 
9254 			if (!scan_freqs_khz)
9255 				freq = MHZ_TO_KHZ(freq);
9256 
9257 			chan = ieee80211_get_channel_khz(wiphy, freq);
9258 			if (!chan) {
9259 				err = -EINVAL;
9260 				goto out_free;
9261 			}
9262 
9263 			/* ignore disabled channels */
9264 			if (chan->flags & IEEE80211_CHAN_DISABLED)
9265 				continue;
9266 
9267 			request->channels[i] = chan;
9268 			i++;
9269 		}
9270 	} else {
9271 		enum nl80211_band band;
9272 
9273 		/* all channels */
9274 		for (band = 0; band < NUM_NL80211_BANDS; band++) {
9275 			int j;
9276 
9277 			if (!wiphy->bands[band])
9278 				continue;
9279 			for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
9280 				struct ieee80211_channel *chan;
9281 
9282 				chan = &wiphy->bands[band]->channels[j];
9283 
9284 				if (chan->flags & IEEE80211_CHAN_DISABLED)
9285 					continue;
9286 
9287 				request->channels[i] = chan;
9288 				i++;
9289 			}
9290 		}
9291 	}
9292 
9293 	if (!i) {
9294 		err = -EINVAL;
9295 		goto out_free;
9296 	}
9297 
9298 	request->n_channels = i;
9299 
9300 	wdev_lock(wdev);
9301 	for (i = 0; i < request->n_channels; i++) {
9302 		struct ieee80211_channel *chan = request->channels[i];
9303 
9304 		/* if we can go off-channel to the target channel we're good */
9305 		if (cfg80211_off_channel_oper_allowed(wdev, chan))
9306 			continue;
9307 
9308 		if (!cfg80211_wdev_on_sub_chan(wdev, chan, true)) {
9309 			wdev_unlock(wdev);
9310 			err = -EBUSY;
9311 			goto out_free;
9312 		}
9313 	}
9314 	wdev_unlock(wdev);
9315 
9316 	i = 0;
9317 	if (n_ssids) {
9318 		nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
9319 			if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
9320 				err = -EINVAL;
9321 				goto out_free;
9322 			}
9323 			request->ssids[i].ssid_len = nla_len(attr);
9324 			memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
9325 			i++;
9326 		}
9327 	}
9328 
9329 	if (info->attrs[NL80211_ATTR_IE]) {
9330 		request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9331 		memcpy((void *)request->ie,
9332 		       nla_data(info->attrs[NL80211_ATTR_IE]),
9333 		       request->ie_len);
9334 	}
9335 
9336 	for (i = 0; i < NUM_NL80211_BANDS; i++)
9337 		if (wiphy->bands[i])
9338 			request->rates[i] =
9339 				(1 << wiphy->bands[i]->n_bitrates) - 1;
9340 
9341 	if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
9342 		nla_for_each_nested(attr,
9343 				    info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
9344 				    tmp) {
9345 			enum nl80211_band band = nla_type(attr);
9346 
9347 			if (band < 0 || band >= NUM_NL80211_BANDS) {
9348 				err = -EINVAL;
9349 				goto out_free;
9350 			}
9351 
9352 			if (!wiphy->bands[band])
9353 				continue;
9354 
9355 			err = ieee80211_get_ratemask(wiphy->bands[band],
9356 						     nla_data(attr),
9357 						     nla_len(attr),
9358 						     &request->rates[band]);
9359 			if (err)
9360 				goto out_free;
9361 		}
9362 	}
9363 
9364 	if (info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]) {
9365 		request->duration =
9366 			nla_get_u16(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]);
9367 		request->duration_mandatory =
9368 			nla_get_flag(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION_MANDATORY]);
9369 	}
9370 
9371 	err = nl80211_check_scan_flags(wiphy, wdev, request, info->attrs,
9372 				       false);
9373 	if (err)
9374 		goto out_free;
9375 
9376 	request->no_cck =
9377 		nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
9378 
9379 	/* Initial implementation used NL80211_ATTR_MAC to set the specific
9380 	 * BSSID to scan for. This was problematic because that same attribute
9381 	 * was already used for another purpose (local random MAC address). The
9382 	 * NL80211_ATTR_BSSID attribute was added to fix this. For backwards
9383 	 * compatibility with older userspace components, also use the
9384 	 * NL80211_ATTR_MAC value here if it can be determined to be used for
9385 	 * the specific BSSID use case instead of the random MAC address
9386 	 * (NL80211_ATTR_SCAN_FLAGS is used to enable random MAC address use).
9387 	 */
9388 	if (info->attrs[NL80211_ATTR_BSSID])
9389 		memcpy(request->bssid,
9390 		       nla_data(info->attrs[NL80211_ATTR_BSSID]), ETH_ALEN);
9391 	else if (!(request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) &&
9392 		 info->attrs[NL80211_ATTR_MAC])
9393 		memcpy(request->bssid, nla_data(info->attrs[NL80211_ATTR_MAC]),
9394 		       ETH_ALEN);
9395 	else
9396 		eth_broadcast_addr(request->bssid);
9397 
9398 	request->wdev = wdev;
9399 	request->wiphy = &rdev->wiphy;
9400 	request->scan_start = jiffies;
9401 
9402 	rdev->scan_req = request;
9403 	err = cfg80211_scan(rdev);
9404 
9405 	if (err)
9406 		goto out_free;
9407 
9408 	nl80211_send_scan_start(rdev, wdev);
9409 	dev_hold(wdev->netdev);
9410 
9411 	return 0;
9412 
9413  out_free:
9414 	rdev->scan_req = NULL;
9415 	kfree(request);
9416 
9417 	return err;
9418 }
9419 
nl80211_abort_scan(struct sk_buff * skb,struct genl_info * info)9420 static int nl80211_abort_scan(struct sk_buff *skb, struct genl_info *info)
9421 {
9422 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
9423 	struct wireless_dev *wdev = info->user_ptr[1];
9424 
9425 	if (!rdev->ops->abort_scan)
9426 		return -EOPNOTSUPP;
9427 
9428 	if (rdev->scan_msg)
9429 		return 0;
9430 
9431 	if (!rdev->scan_req)
9432 		return -ENOENT;
9433 
9434 	rdev_abort_scan(rdev, wdev);
9435 	return 0;
9436 }
9437 
9438 static int
nl80211_parse_sched_scan_plans(struct wiphy * wiphy,int n_plans,struct cfg80211_sched_scan_request * request,struct nlattr ** attrs)9439 nl80211_parse_sched_scan_plans(struct wiphy *wiphy, int n_plans,
9440 			       struct cfg80211_sched_scan_request *request,
9441 			       struct nlattr **attrs)
9442 {
9443 	int tmp, err, i = 0;
9444 	struct nlattr *attr;
9445 
9446 	if (!attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) {
9447 		u32 interval;
9448 
9449 		/*
9450 		 * If scan plans are not specified,
9451 		 * %NL80211_ATTR_SCHED_SCAN_INTERVAL will be specified. In this
9452 		 * case one scan plan will be set with the specified scan
9453 		 * interval and infinite number of iterations.
9454 		 */
9455 		interval = nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
9456 		if (!interval)
9457 			return -EINVAL;
9458 
9459 		request->scan_plans[0].interval =
9460 			DIV_ROUND_UP(interval, MSEC_PER_SEC);
9461 		if (!request->scan_plans[0].interval)
9462 			return -EINVAL;
9463 
9464 		if (request->scan_plans[0].interval >
9465 		    wiphy->max_sched_scan_plan_interval)
9466 			request->scan_plans[0].interval =
9467 				wiphy->max_sched_scan_plan_interval;
9468 
9469 		return 0;
9470 	}
9471 
9472 	nla_for_each_nested(attr, attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp) {
9473 		struct nlattr *plan[NL80211_SCHED_SCAN_PLAN_MAX + 1];
9474 
9475 		if (WARN_ON(i >= n_plans))
9476 			return -EINVAL;
9477 
9478 		err = nla_parse_nested_deprecated(plan,
9479 						  NL80211_SCHED_SCAN_PLAN_MAX,
9480 						  attr, nl80211_plan_policy,
9481 						  NULL);
9482 		if (err)
9483 			return err;
9484 
9485 		if (!plan[NL80211_SCHED_SCAN_PLAN_INTERVAL])
9486 			return -EINVAL;
9487 
9488 		request->scan_plans[i].interval =
9489 			nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_INTERVAL]);
9490 		if (!request->scan_plans[i].interval ||
9491 		    request->scan_plans[i].interval >
9492 		    wiphy->max_sched_scan_plan_interval)
9493 			return -EINVAL;
9494 
9495 		if (plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]) {
9496 			request->scan_plans[i].iterations =
9497 				nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]);
9498 			if (!request->scan_plans[i].iterations ||
9499 			    (request->scan_plans[i].iterations >
9500 			     wiphy->max_sched_scan_plan_iterations))
9501 				return -EINVAL;
9502 		} else if (i < n_plans - 1) {
9503 			/*
9504 			 * All scan plans but the last one must specify
9505 			 * a finite number of iterations
9506 			 */
9507 			return -EINVAL;
9508 		}
9509 
9510 		i++;
9511 	}
9512 
9513 	/*
9514 	 * The last scan plan must not specify the number of
9515 	 * iterations, it is supposed to run infinitely
9516 	 */
9517 	if (request->scan_plans[n_plans - 1].iterations)
9518 		return  -EINVAL;
9519 
9520 	return 0;
9521 }
9522 
9523 static int
nl80211_parse_sched_scan_per_band_rssi(struct wiphy * wiphy,struct cfg80211_match_set * match_sets,struct nlattr * tb_band_rssi,s32 rssi_thold)9524 nl80211_parse_sched_scan_per_band_rssi(struct wiphy *wiphy,
9525 				       struct cfg80211_match_set *match_sets,
9526 				       struct nlattr *tb_band_rssi,
9527 				       s32 rssi_thold)
9528 {
9529 	struct nlattr *attr;
9530 	int i, tmp, ret = 0;
9531 
9532 	if (!wiphy_ext_feature_isset(wiphy,
9533 		    NL80211_EXT_FEATURE_SCHED_SCAN_BAND_SPECIFIC_RSSI_THOLD)) {
9534 		if (tb_band_rssi)
9535 			ret = -EOPNOTSUPP;
9536 		else
9537 			for (i = 0; i < NUM_NL80211_BANDS; i++)
9538 				match_sets->per_band_rssi_thold[i] =
9539 					NL80211_SCAN_RSSI_THOLD_OFF;
9540 		return ret;
9541 	}
9542 
9543 	for (i = 0; i < NUM_NL80211_BANDS; i++)
9544 		match_sets->per_band_rssi_thold[i] = rssi_thold;
9545 
9546 	nla_for_each_nested(attr, tb_band_rssi, tmp) {
9547 		enum nl80211_band band = nla_type(attr);
9548 
9549 		if (band < 0 || band >= NUM_NL80211_BANDS)
9550 			return -EINVAL;
9551 
9552 		match_sets->per_band_rssi_thold[band] =	nla_get_s32(attr);
9553 	}
9554 
9555 	return 0;
9556 }
9557 
9558 static struct cfg80211_sched_scan_request *
nl80211_parse_sched_scan(struct wiphy * wiphy,struct wireless_dev * wdev,struct nlattr ** attrs,int max_match_sets)9559 nl80211_parse_sched_scan(struct wiphy *wiphy, struct wireless_dev *wdev,
9560 			 struct nlattr **attrs, int max_match_sets)
9561 {
9562 	struct cfg80211_sched_scan_request *request;
9563 	struct nlattr *attr;
9564 	int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i, n_plans = 0;
9565 	enum nl80211_band band;
9566 	size_t ie_len, size;
9567 	struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
9568 	s32 default_match_rssi = NL80211_SCAN_RSSI_THOLD_OFF;
9569 
9570 	if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
9571 		n_channels = validate_scan_freqs(
9572 				attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
9573 		if (!n_channels)
9574 			return ERR_PTR(-EINVAL);
9575 	} else {
9576 		n_channels = ieee80211_get_num_supported_channels(wiphy);
9577 	}
9578 
9579 	if (attrs[NL80211_ATTR_SCAN_SSIDS])
9580 		nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS],
9581 				    tmp)
9582 			n_ssids++;
9583 
9584 	if (n_ssids > wiphy->max_sched_scan_ssids)
9585 		return ERR_PTR(-EINVAL);
9586 
9587 	/*
9588 	 * First, count the number of 'real' matchsets. Due to an issue with
9589 	 * the old implementation, matchsets containing only the RSSI attribute
9590 	 * (NL80211_SCHED_SCAN_MATCH_ATTR_RSSI) are considered as the 'default'
9591 	 * RSSI for all matchsets, rather than their own matchset for reporting
9592 	 * all APs with a strong RSSI. This is needed to be compatible with
9593 	 * older userspace that treated a matchset with only the RSSI as the
9594 	 * global RSSI for all other matchsets - if there are other matchsets.
9595 	 */
9596 	if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
9597 		nla_for_each_nested(attr,
9598 				    attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
9599 				    tmp) {
9600 			struct nlattr *rssi;
9601 
9602 			err = nla_parse_nested_deprecated(tb,
9603 							  NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
9604 							  attr,
9605 							  nl80211_match_policy,
9606 							  NULL);
9607 			if (err)
9608 				return ERR_PTR(err);
9609 
9610 			/* SSID and BSSID are mutually exclusive */
9611 			if (tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID] &&
9612 			    tb[NL80211_SCHED_SCAN_MATCH_ATTR_BSSID])
9613 				return ERR_PTR(-EINVAL);
9614 
9615 			/* add other standalone attributes here */
9616 			if (tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID] ||
9617 			    tb[NL80211_SCHED_SCAN_MATCH_ATTR_BSSID]) {
9618 				n_match_sets++;
9619 				continue;
9620 			}
9621 			rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
9622 			if (rssi)
9623 				default_match_rssi = nla_get_s32(rssi);
9624 		}
9625 	}
9626 
9627 	/* However, if there's no other matchset, add the RSSI one */
9628 	if (!n_match_sets && default_match_rssi != NL80211_SCAN_RSSI_THOLD_OFF)
9629 		n_match_sets = 1;
9630 
9631 	if (n_match_sets > max_match_sets)
9632 		return ERR_PTR(-EINVAL);
9633 
9634 	if (attrs[NL80211_ATTR_IE])
9635 		ie_len = nla_len(attrs[NL80211_ATTR_IE]);
9636 	else
9637 		ie_len = 0;
9638 
9639 	if (ie_len > wiphy->max_sched_scan_ie_len)
9640 		return ERR_PTR(-EINVAL);
9641 
9642 	if (attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) {
9643 		/*
9644 		 * NL80211_ATTR_SCHED_SCAN_INTERVAL must not be specified since
9645 		 * each scan plan already specifies its own interval
9646 		 */
9647 		if (attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
9648 			return ERR_PTR(-EINVAL);
9649 
9650 		nla_for_each_nested(attr,
9651 				    attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp)
9652 			n_plans++;
9653 	} else {
9654 		/*
9655 		 * The scan interval attribute is kept for backward
9656 		 * compatibility. If no scan plans are specified and sched scan
9657 		 * interval is specified, one scan plan will be set with this
9658 		 * scan interval and infinite number of iterations.
9659 		 */
9660 		if (!attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
9661 			return ERR_PTR(-EINVAL);
9662 
9663 		n_plans = 1;
9664 	}
9665 
9666 	if (!n_plans || n_plans > wiphy->max_sched_scan_plans)
9667 		return ERR_PTR(-EINVAL);
9668 
9669 	if (!wiphy_ext_feature_isset(
9670 		    wiphy, NL80211_EXT_FEATURE_SCHED_SCAN_RELATIVE_RSSI) &&
9671 	    (attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI] ||
9672 	     attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]))
9673 		return ERR_PTR(-EINVAL);
9674 
9675 	size = struct_size(request, channels, n_channels);
9676 	size = size_add(size, array_size(sizeof(*request->ssids), n_ssids));
9677 	size = size_add(size, array_size(sizeof(*request->match_sets),
9678 					 n_match_sets));
9679 	size = size_add(size, array_size(sizeof(*request->scan_plans),
9680 					 n_plans));
9681 	size = size_add(size, ie_len);
9682 	request = kzalloc(size, GFP_KERNEL);
9683 	if (!request)
9684 		return ERR_PTR(-ENOMEM);
9685 
9686 	if (n_ssids)
9687 		request->ssids = (void *)request +
9688 			struct_size(request, channels, n_channels);
9689 	request->n_ssids = n_ssids;
9690 	if (ie_len) {
9691 		if (n_ssids)
9692 			request->ie = (void *)(request->ssids + n_ssids);
9693 		else
9694 			request->ie = (void *)(request->channels + n_channels);
9695 	}
9696 
9697 	if (n_match_sets) {
9698 		if (request->ie)
9699 			request->match_sets = (void *)(request->ie + ie_len);
9700 		else if (n_ssids)
9701 			request->match_sets =
9702 				(void *)(request->ssids + n_ssids);
9703 		else
9704 			request->match_sets =
9705 				(void *)(request->channels + n_channels);
9706 	}
9707 	request->n_match_sets = n_match_sets;
9708 
9709 	if (n_match_sets)
9710 		request->scan_plans = (void *)(request->match_sets +
9711 					       n_match_sets);
9712 	else if (request->ie)
9713 		request->scan_plans = (void *)(request->ie + ie_len);
9714 	else if (n_ssids)
9715 		request->scan_plans = (void *)(request->ssids + n_ssids);
9716 	else
9717 		request->scan_plans = (void *)(request->channels + n_channels);
9718 
9719 	request->n_scan_plans = n_plans;
9720 
9721 	i = 0;
9722 	if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
9723 		/* user specified, bail out if channel not found */
9724 		nla_for_each_nested(attr,
9725 				    attrs[NL80211_ATTR_SCAN_FREQUENCIES],
9726 				    tmp) {
9727 			struct ieee80211_channel *chan;
9728 
9729 			chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
9730 
9731 			if (!chan) {
9732 				err = -EINVAL;
9733 				goto out_free;
9734 			}
9735 
9736 			/* ignore disabled channels */
9737 			if (chan->flags & IEEE80211_CHAN_DISABLED)
9738 				continue;
9739 
9740 			request->channels[i] = chan;
9741 			i++;
9742 		}
9743 	} else {
9744 		/* all channels */
9745 		for (band = 0; band < NUM_NL80211_BANDS; band++) {
9746 			int j;
9747 
9748 			if (!wiphy->bands[band])
9749 				continue;
9750 			for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
9751 				struct ieee80211_channel *chan;
9752 
9753 				chan = &wiphy->bands[band]->channels[j];
9754 
9755 				if (chan->flags & IEEE80211_CHAN_DISABLED)
9756 					continue;
9757 
9758 				request->channels[i] = chan;
9759 				i++;
9760 			}
9761 		}
9762 	}
9763 
9764 	if (!i) {
9765 		err = -EINVAL;
9766 		goto out_free;
9767 	}
9768 
9769 	request->n_channels = i;
9770 
9771 	i = 0;
9772 	if (n_ssids) {
9773 		nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS],
9774 				    tmp) {
9775 			if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
9776 				err = -EINVAL;
9777 				goto out_free;
9778 			}
9779 			request->ssids[i].ssid_len = nla_len(attr);
9780 			memcpy(request->ssids[i].ssid, nla_data(attr),
9781 			       nla_len(attr));
9782 			i++;
9783 		}
9784 	}
9785 
9786 	i = 0;
9787 	if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
9788 		nla_for_each_nested(attr,
9789 				    attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
9790 				    tmp) {
9791 			struct nlattr *ssid, *bssid, *rssi;
9792 
9793 			err = nla_parse_nested_deprecated(tb,
9794 							  NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
9795 							  attr,
9796 							  nl80211_match_policy,
9797 							  NULL);
9798 			if (err)
9799 				goto out_free;
9800 			ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
9801 			bssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_BSSID];
9802 
9803 			if (!ssid && !bssid) {
9804 				i++;
9805 				continue;
9806 			}
9807 
9808 			if (WARN_ON(i >= n_match_sets)) {
9809 				/* this indicates a programming error,
9810 				 * the loop above should have verified
9811 				 * things properly
9812 				 */
9813 				err = -EINVAL;
9814 				goto out_free;
9815 			}
9816 
9817 			if (ssid) {
9818 				memcpy(request->match_sets[i].ssid.ssid,
9819 				       nla_data(ssid), nla_len(ssid));
9820 				request->match_sets[i].ssid.ssid_len =
9821 					nla_len(ssid);
9822 			}
9823 			if (bssid)
9824 				memcpy(request->match_sets[i].bssid,
9825 				       nla_data(bssid), ETH_ALEN);
9826 
9827 			/* special attribute - old implementation w/a */
9828 			request->match_sets[i].rssi_thold = default_match_rssi;
9829 			rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
9830 			if (rssi)
9831 				request->match_sets[i].rssi_thold =
9832 					nla_get_s32(rssi);
9833 
9834 			/* Parse per band RSSI attribute */
9835 			err = nl80211_parse_sched_scan_per_band_rssi(wiphy,
9836 				&request->match_sets[i],
9837 				tb[NL80211_SCHED_SCAN_MATCH_PER_BAND_RSSI],
9838 				request->match_sets[i].rssi_thold);
9839 			if (err)
9840 				goto out_free;
9841 
9842 			i++;
9843 		}
9844 
9845 		/* there was no other matchset, so the RSSI one is alone */
9846 		if (i == 0 && n_match_sets)
9847 			request->match_sets[0].rssi_thold = default_match_rssi;
9848 
9849 		request->min_rssi_thold = INT_MAX;
9850 		for (i = 0; i < n_match_sets; i++)
9851 			request->min_rssi_thold =
9852 				min(request->match_sets[i].rssi_thold,
9853 				    request->min_rssi_thold);
9854 	} else {
9855 		request->min_rssi_thold = NL80211_SCAN_RSSI_THOLD_OFF;
9856 	}
9857 
9858 	if (ie_len) {
9859 		request->ie_len = ie_len;
9860 		memcpy((void *)request->ie,
9861 		       nla_data(attrs[NL80211_ATTR_IE]),
9862 		       request->ie_len);
9863 	}
9864 
9865 	err = nl80211_check_scan_flags(wiphy, wdev, request, attrs, true);
9866 	if (err)
9867 		goto out_free;
9868 
9869 	if (attrs[NL80211_ATTR_SCHED_SCAN_DELAY])
9870 		request->delay =
9871 			nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_DELAY]);
9872 
9873 	if (attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI]) {
9874 		request->relative_rssi = nla_get_s8(
9875 			attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI]);
9876 		request->relative_rssi_set = true;
9877 	}
9878 
9879 	if (request->relative_rssi_set &&
9880 	    attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]) {
9881 		struct nl80211_bss_select_rssi_adjust *rssi_adjust;
9882 
9883 		rssi_adjust = nla_data(
9884 			attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]);
9885 		request->rssi_adjust.band = rssi_adjust->band;
9886 		request->rssi_adjust.delta = rssi_adjust->delta;
9887 		if (!is_band_valid(wiphy, request->rssi_adjust.band)) {
9888 			err = -EINVAL;
9889 			goto out_free;
9890 		}
9891 	}
9892 
9893 	err = nl80211_parse_sched_scan_plans(wiphy, n_plans, request, attrs);
9894 	if (err)
9895 		goto out_free;
9896 
9897 	request->scan_start = jiffies;
9898 
9899 	return request;
9900 
9901 out_free:
9902 	kfree(request);
9903 	return ERR_PTR(err);
9904 }
9905 
nl80211_start_sched_scan(struct sk_buff * skb,struct genl_info * info)9906 static int nl80211_start_sched_scan(struct sk_buff *skb,
9907 				    struct genl_info *info)
9908 {
9909 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
9910 	struct net_device *dev = info->user_ptr[1];
9911 	struct wireless_dev *wdev = dev->ieee80211_ptr;
9912 	struct cfg80211_sched_scan_request *sched_scan_req;
9913 	bool want_multi;
9914 	int err;
9915 
9916 	if (!rdev->wiphy.max_sched_scan_reqs || !rdev->ops->sched_scan_start)
9917 		return -EOPNOTSUPP;
9918 
9919 	want_multi = info->attrs[NL80211_ATTR_SCHED_SCAN_MULTI];
9920 	err = cfg80211_sched_scan_req_possible(rdev, want_multi);
9921 	if (err)
9922 		return err;
9923 
9924 	sched_scan_req = nl80211_parse_sched_scan(&rdev->wiphy, wdev,
9925 						  info->attrs,
9926 						  rdev->wiphy.max_match_sets);
9927 
9928 	err = PTR_ERR_OR_ZERO(sched_scan_req);
9929 	if (err)
9930 		goto out_err;
9931 
9932 	/* leave request id zero for legacy request
9933 	 * or if driver does not support multi-scheduled scan
9934 	 */
9935 	if (want_multi && rdev->wiphy.max_sched_scan_reqs > 1)
9936 		sched_scan_req->reqid = cfg80211_assign_cookie(rdev);
9937 
9938 	err = rdev_sched_scan_start(rdev, dev, sched_scan_req);
9939 	if (err)
9940 		goto out_free;
9941 
9942 	sched_scan_req->dev = dev;
9943 	sched_scan_req->wiphy = &rdev->wiphy;
9944 
9945 	if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
9946 		sched_scan_req->owner_nlportid = info->snd_portid;
9947 
9948 	cfg80211_add_sched_scan_req(rdev, sched_scan_req);
9949 
9950 	nl80211_send_sched_scan(sched_scan_req, NL80211_CMD_START_SCHED_SCAN);
9951 	return 0;
9952 
9953 out_free:
9954 	kfree(sched_scan_req);
9955 out_err:
9956 	return err;
9957 }
9958 
nl80211_stop_sched_scan(struct sk_buff * skb,struct genl_info * info)9959 static int nl80211_stop_sched_scan(struct sk_buff *skb,
9960 				   struct genl_info *info)
9961 {
9962 	struct cfg80211_sched_scan_request *req;
9963 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
9964 	u64 cookie;
9965 
9966 	if (!rdev->wiphy.max_sched_scan_reqs || !rdev->ops->sched_scan_stop)
9967 		return -EOPNOTSUPP;
9968 
9969 	if (info->attrs[NL80211_ATTR_COOKIE]) {
9970 		cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
9971 		return __cfg80211_stop_sched_scan(rdev, cookie, false);
9972 	}
9973 
9974 	req = list_first_or_null_rcu(&rdev->sched_scan_req_list,
9975 				     struct cfg80211_sched_scan_request,
9976 				     list);
9977 	if (!req || req->reqid ||
9978 	    (req->owner_nlportid &&
9979 	     req->owner_nlportid != info->snd_portid))
9980 		return -ENOENT;
9981 
9982 	return cfg80211_stop_sched_scan_req(rdev, req, false);
9983 }
9984 
nl80211_start_radar_detection(struct sk_buff * skb,struct genl_info * info)9985 static int nl80211_start_radar_detection(struct sk_buff *skb,
9986 					 struct genl_info *info)
9987 {
9988 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
9989 	struct net_device *dev = info->user_ptr[1];
9990 	struct wireless_dev *wdev = dev->ieee80211_ptr;
9991 	struct wiphy *wiphy = wdev->wiphy;
9992 	struct cfg80211_chan_def chandef;
9993 	enum nl80211_dfs_regions dfs_region;
9994 	unsigned int cac_time_ms;
9995 	int err = -EINVAL;
9996 
9997 	flush_delayed_work(&rdev->dfs_update_channels_wk);
9998 
9999 	wiphy_lock(wiphy);
10000 
10001 	dfs_region = reg_get_dfs_region(wiphy);
10002 	if (dfs_region == NL80211_DFS_UNSET)
10003 		goto unlock;
10004 
10005 	err = nl80211_parse_chandef(rdev, info, &chandef);
10006 	if (err)
10007 		goto unlock;
10008 
10009 	err = cfg80211_chandef_dfs_required(wiphy, &chandef, wdev->iftype);
10010 	if (err < 0)
10011 		goto unlock;
10012 
10013 	if (err == 0) {
10014 		err = -EINVAL;
10015 		goto unlock;
10016 	}
10017 
10018 	if (!cfg80211_chandef_dfs_usable(wiphy, &chandef)) {
10019 		err = -EINVAL;
10020 		goto unlock;
10021 	}
10022 
10023 	if (nla_get_flag(info->attrs[NL80211_ATTR_RADAR_BACKGROUND])) {
10024 		err = cfg80211_start_background_radar_detection(rdev, wdev,
10025 								&chandef);
10026 		goto unlock;
10027 	}
10028 
10029 	if (netif_carrier_ok(dev)) {
10030 		err = -EBUSY;
10031 		goto unlock;
10032 	}
10033 
10034 	if (wdev->cac_started) {
10035 		err = -EBUSY;
10036 		goto unlock;
10037 	}
10038 
10039 	/* CAC start is offloaded to HW and can't be started manually */
10040 	if (wiphy_ext_feature_isset(wiphy, NL80211_EXT_FEATURE_DFS_OFFLOAD)) {
10041 		err = -EOPNOTSUPP;
10042 		goto unlock;
10043 	}
10044 
10045 	if (!rdev->ops->start_radar_detection) {
10046 		err = -EOPNOTSUPP;
10047 		goto unlock;
10048 	}
10049 
10050 	cac_time_ms = cfg80211_chandef_dfs_cac_time(&rdev->wiphy, &chandef);
10051 	if (WARN_ON(!cac_time_ms))
10052 		cac_time_ms = IEEE80211_DFS_MIN_CAC_TIME_MS;
10053 
10054 	err = rdev_start_radar_detection(rdev, dev, &chandef, cac_time_ms);
10055 	if (!err) {
10056 		switch (wdev->iftype) {
10057 		case NL80211_IFTYPE_AP:
10058 		case NL80211_IFTYPE_P2P_GO:
10059 			wdev->links[0].ap.chandef = chandef;
10060 			break;
10061 		case NL80211_IFTYPE_ADHOC:
10062 			wdev->u.ibss.chandef = chandef;
10063 			break;
10064 		case NL80211_IFTYPE_MESH_POINT:
10065 			wdev->u.mesh.chandef = chandef;
10066 			break;
10067 		default:
10068 			break;
10069 		}
10070 		wdev->cac_started = true;
10071 		wdev->cac_start_time = jiffies;
10072 		wdev->cac_time_ms = cac_time_ms;
10073 	}
10074 unlock:
10075 	wiphy_unlock(wiphy);
10076 
10077 	return err;
10078 }
10079 
nl80211_notify_radar_detection(struct sk_buff * skb,struct genl_info * info)10080 static int nl80211_notify_radar_detection(struct sk_buff *skb,
10081 					  struct genl_info *info)
10082 {
10083 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
10084 	struct net_device *dev = info->user_ptr[1];
10085 	struct wireless_dev *wdev = dev->ieee80211_ptr;
10086 	struct wiphy *wiphy = wdev->wiphy;
10087 	struct cfg80211_chan_def chandef;
10088 	enum nl80211_dfs_regions dfs_region;
10089 	int err;
10090 
10091 	dfs_region = reg_get_dfs_region(wiphy);
10092 	if (dfs_region == NL80211_DFS_UNSET) {
10093 		GENL_SET_ERR_MSG(info,
10094 				 "DFS Region is not set. Unexpected Radar indication");
10095 		return -EINVAL;
10096 	}
10097 
10098 	err = nl80211_parse_chandef(rdev, info, &chandef);
10099 	if (err) {
10100 		GENL_SET_ERR_MSG(info, "Unable to extract chandef info");
10101 		return err;
10102 	}
10103 
10104 	err = cfg80211_chandef_dfs_required(wiphy, &chandef, wdev->iftype);
10105 	if (err < 0) {
10106 		GENL_SET_ERR_MSG(info, "chandef is invalid");
10107 		return err;
10108 	}
10109 
10110 	if (err == 0) {
10111 		GENL_SET_ERR_MSG(info,
10112 				 "Unexpected Radar indication for chandef/iftype");
10113 		return -EINVAL;
10114 	}
10115 
10116 	/* Do not process this notification if radar is already detected
10117 	 * by kernel on this channel, and return success.
10118 	 */
10119 	if (chandef.chan->dfs_state == NL80211_DFS_UNAVAILABLE)
10120 		return 0;
10121 
10122 	cfg80211_set_dfs_state(wiphy, &chandef, NL80211_DFS_UNAVAILABLE);
10123 
10124 	cfg80211_sched_dfs_chan_update(rdev);
10125 
10126 	rdev->radar_chandef = chandef;
10127 
10128 	/* Propagate this notification to other radios as well */
10129 	queue_work(cfg80211_wq, &rdev->propagate_radar_detect_wk);
10130 
10131 	return 0;
10132 }
10133 
nl80211_channel_switch(struct sk_buff * skb,struct genl_info * info)10134 static int nl80211_channel_switch(struct sk_buff *skb, struct genl_info *info)
10135 {
10136 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
10137 	unsigned int link_id = nl80211_link_id(info->attrs);
10138 	struct net_device *dev = info->user_ptr[1];
10139 	struct wireless_dev *wdev = dev->ieee80211_ptr;
10140 	struct cfg80211_csa_settings params;
10141 	struct nlattr **csa_attrs = NULL;
10142 	int err;
10143 	bool need_new_beacon = false;
10144 	bool need_handle_dfs_flag = true;
10145 	int len, i;
10146 	u32 cs_count;
10147 
10148 	if (!rdev->ops->channel_switch ||
10149 	    !(rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH))
10150 		return -EOPNOTSUPP;
10151 
10152 	switch (dev->ieee80211_ptr->iftype) {
10153 	case NL80211_IFTYPE_AP:
10154 	case NL80211_IFTYPE_P2P_GO:
10155 		need_new_beacon = true;
10156 		/* For all modes except AP the handle_dfs flag needs to be
10157 		 * supplied to tell the kernel that userspace will handle radar
10158 		 * events when they happen. Otherwise a switch to a channel
10159 		 * requiring DFS will be rejected.
10160 		 */
10161 		need_handle_dfs_flag = false;
10162 
10163 		/* useless if AP is not running */
10164 		if (!wdev->links[link_id].ap.beacon_interval)
10165 			return -ENOTCONN;
10166 		break;
10167 	case NL80211_IFTYPE_ADHOC:
10168 		if (!wdev->u.ibss.ssid_len)
10169 			return -ENOTCONN;
10170 		break;
10171 	case NL80211_IFTYPE_MESH_POINT:
10172 		if (!wdev->u.mesh.id_len)
10173 			return -ENOTCONN;
10174 		break;
10175 	default:
10176 		return -EOPNOTSUPP;
10177 	}
10178 
10179 	memset(&params, 0, sizeof(params));
10180 	params.beacon_csa.ftm_responder = -1;
10181 
10182 	if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
10183 	    !info->attrs[NL80211_ATTR_CH_SWITCH_COUNT])
10184 		return -EINVAL;
10185 
10186 	/* only important for AP, IBSS and mesh create IEs internally */
10187 	if (need_new_beacon && !info->attrs[NL80211_ATTR_CSA_IES])
10188 		return -EINVAL;
10189 
10190 	/* Even though the attribute is u32, the specification says
10191 	 * u8, so let's make sure we don't overflow.
10192 	 */
10193 	cs_count = nla_get_u32(info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]);
10194 	if (cs_count > 255)
10195 		return -EINVAL;
10196 
10197 	params.count = cs_count;
10198 
10199 	if (!need_new_beacon)
10200 		goto skip_beacons;
10201 
10202 	err = nl80211_parse_beacon(rdev, info->attrs, &params.beacon_after,
10203 				   info->extack);
10204 	if (err)
10205 		goto free;
10206 
10207 	csa_attrs = kcalloc(NL80211_ATTR_MAX + 1, sizeof(*csa_attrs),
10208 			    GFP_KERNEL);
10209 	if (!csa_attrs) {
10210 		err = -ENOMEM;
10211 		goto free;
10212 	}
10213 
10214 	err = nla_parse_nested_deprecated(csa_attrs, NL80211_ATTR_MAX,
10215 					  info->attrs[NL80211_ATTR_CSA_IES],
10216 					  nl80211_policy, info->extack);
10217 	if (err)
10218 		goto free;
10219 
10220 	err = nl80211_parse_beacon(rdev, csa_attrs, &params.beacon_csa,
10221 				   info->extack);
10222 	if (err)
10223 		goto free;
10224 
10225 	if (!csa_attrs[NL80211_ATTR_CNTDWN_OFFS_BEACON]) {
10226 		err = -EINVAL;
10227 		goto free;
10228 	}
10229 
10230 	len = nla_len(csa_attrs[NL80211_ATTR_CNTDWN_OFFS_BEACON]);
10231 	if (!len || (len % sizeof(u16))) {
10232 		err = -EINVAL;
10233 		goto free;
10234 	}
10235 
10236 	params.n_counter_offsets_beacon = len / sizeof(u16);
10237 	if (rdev->wiphy.max_num_csa_counters &&
10238 	    (params.n_counter_offsets_beacon >
10239 	     rdev->wiphy.max_num_csa_counters)) {
10240 		err = -EINVAL;
10241 		goto free;
10242 	}
10243 
10244 	params.counter_offsets_beacon =
10245 		nla_data(csa_attrs[NL80211_ATTR_CNTDWN_OFFS_BEACON]);
10246 
10247 	/* sanity checks - counters should fit and be the same */
10248 	for (i = 0; i < params.n_counter_offsets_beacon; i++) {
10249 		u16 offset = params.counter_offsets_beacon[i];
10250 
10251 		if (offset >= params.beacon_csa.tail_len) {
10252 			err = -EINVAL;
10253 			goto free;
10254 		}
10255 
10256 		if (params.beacon_csa.tail[offset] != params.count) {
10257 			err = -EINVAL;
10258 			goto free;
10259 		}
10260 	}
10261 
10262 	if (csa_attrs[NL80211_ATTR_CNTDWN_OFFS_PRESP]) {
10263 		len = nla_len(csa_attrs[NL80211_ATTR_CNTDWN_OFFS_PRESP]);
10264 		if (!len || (len % sizeof(u16))) {
10265 			err = -EINVAL;
10266 			goto free;
10267 		}
10268 
10269 		params.n_counter_offsets_presp = len / sizeof(u16);
10270 		if (rdev->wiphy.max_num_csa_counters &&
10271 		    (params.n_counter_offsets_presp >
10272 		     rdev->wiphy.max_num_csa_counters)) {
10273 			err = -EINVAL;
10274 			goto free;
10275 		}
10276 
10277 		params.counter_offsets_presp =
10278 			nla_data(csa_attrs[NL80211_ATTR_CNTDWN_OFFS_PRESP]);
10279 
10280 		/* sanity checks - counters should fit and be the same */
10281 		for (i = 0; i < params.n_counter_offsets_presp; i++) {
10282 			u16 offset = params.counter_offsets_presp[i];
10283 
10284 			if (offset >= params.beacon_csa.probe_resp_len) {
10285 				err = -EINVAL;
10286 				goto free;
10287 			}
10288 
10289 			if (params.beacon_csa.probe_resp[offset] !=
10290 			    params.count) {
10291 				err = -EINVAL;
10292 				goto free;
10293 			}
10294 		}
10295 	}
10296 
10297 skip_beacons:
10298 	err = nl80211_parse_chandef(rdev, info, &params.chandef);
10299 	if (err)
10300 		goto free;
10301 
10302 	if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &params.chandef,
10303 					   wdev->iftype)) {
10304 		err = -EINVAL;
10305 		goto free;
10306 	}
10307 
10308 	err = cfg80211_chandef_dfs_required(wdev->wiphy,
10309 					    &params.chandef,
10310 					    wdev->iftype);
10311 	if (err < 0)
10312 		goto free;
10313 
10314 	if (err > 0) {
10315 		params.radar_required = true;
10316 		if (need_handle_dfs_flag &&
10317 		    !nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS])) {
10318 			err = -EINVAL;
10319 			goto free;
10320 		}
10321 	}
10322 
10323 	if (info->attrs[NL80211_ATTR_CH_SWITCH_BLOCK_TX])
10324 		params.block_tx = true;
10325 
10326 	if (info->attrs[NL80211_ATTR_PUNCT_BITMAP]) {
10327 		err = nl80211_parse_punct_bitmap(rdev, info,
10328 						 &params.chandef,
10329 						 &params.punct_bitmap);
10330 		if (err)
10331 			goto free;
10332 	}
10333 
10334 	wdev_lock(wdev);
10335 	err = rdev_channel_switch(rdev, dev, &params);
10336 	wdev_unlock(wdev);
10337 
10338 free:
10339 	kfree(params.beacon_after.mbssid_ies);
10340 	kfree(params.beacon_csa.mbssid_ies);
10341 	kfree(params.beacon_after.rnr_ies);
10342 	kfree(params.beacon_csa.rnr_ies);
10343 	kfree(csa_attrs);
10344 	return err;
10345 }
10346 
nl80211_send_bss(struct sk_buff * msg,struct netlink_callback * cb,u32 seq,int flags,struct cfg80211_registered_device * rdev,struct wireless_dev * wdev,struct cfg80211_internal_bss * intbss)10347 static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
10348 			    u32 seq, int flags,
10349 			    struct cfg80211_registered_device *rdev,
10350 			    struct wireless_dev *wdev,
10351 			    struct cfg80211_internal_bss *intbss)
10352 {
10353 	struct cfg80211_bss *res = &intbss->pub;
10354 	const struct cfg80211_bss_ies *ies;
10355 	unsigned int link_id;
10356 	void *hdr;
10357 	struct nlattr *bss;
10358 
10359 	ASSERT_WDEV_LOCK(wdev);
10360 
10361 	hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
10362 			     NL80211_CMD_NEW_SCAN_RESULTS);
10363 	if (!hdr)
10364 		return -1;
10365 
10366 	genl_dump_check_consistent(cb, hdr);
10367 
10368 	if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation))
10369 		goto nla_put_failure;
10370 	if (wdev->netdev &&
10371 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
10372 		goto nla_put_failure;
10373 	if (nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
10374 			      NL80211_ATTR_PAD))
10375 		goto nla_put_failure;
10376 
10377 	bss = nla_nest_start_noflag(msg, NL80211_ATTR_BSS);
10378 	if (!bss)
10379 		goto nla_put_failure;
10380 	if ((!is_zero_ether_addr(res->bssid) &&
10381 	     nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)))
10382 		goto nla_put_failure;
10383 
10384 	rcu_read_lock();
10385 	/* indicate whether we have probe response data or not */
10386 	if (rcu_access_pointer(res->proberesp_ies) &&
10387 	    nla_put_flag(msg, NL80211_BSS_PRESP_DATA))
10388 		goto fail_unlock_rcu;
10389 
10390 	/* this pointer prefers to be pointed to probe response data
10391 	 * but is always valid
10392 	 */
10393 	ies = rcu_dereference(res->ies);
10394 	if (ies) {
10395 		if (nla_put_u64_64bit(msg, NL80211_BSS_TSF, ies->tsf,
10396 				      NL80211_BSS_PAD))
10397 			goto fail_unlock_rcu;
10398 		if (ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
10399 					ies->len, ies->data))
10400 			goto fail_unlock_rcu;
10401 	}
10402 
10403 	/* and this pointer is always (unless driver didn't know) beacon data */
10404 	ies = rcu_dereference(res->beacon_ies);
10405 	if (ies && ies->from_beacon) {
10406 		if (nla_put_u64_64bit(msg, NL80211_BSS_BEACON_TSF, ies->tsf,
10407 				      NL80211_BSS_PAD))
10408 			goto fail_unlock_rcu;
10409 		if (ies->len && nla_put(msg, NL80211_BSS_BEACON_IES,
10410 					ies->len, ies->data))
10411 			goto fail_unlock_rcu;
10412 	}
10413 	rcu_read_unlock();
10414 
10415 	if (res->beacon_interval &&
10416 	    nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
10417 		goto nla_put_failure;
10418 	if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
10419 	    nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
10420 	    nla_put_u32(msg, NL80211_BSS_FREQUENCY_OFFSET,
10421 			res->channel->freq_offset) ||
10422 	    nla_put_u32(msg, NL80211_BSS_CHAN_WIDTH, res->scan_width) ||
10423 	    nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
10424 			jiffies_to_msecs(jiffies - intbss->ts)))
10425 		goto nla_put_failure;
10426 
10427 	if (intbss->parent_tsf &&
10428 	    (nla_put_u64_64bit(msg, NL80211_BSS_PARENT_TSF,
10429 			       intbss->parent_tsf, NL80211_BSS_PAD) ||
10430 	     nla_put(msg, NL80211_BSS_PARENT_BSSID, ETH_ALEN,
10431 		     intbss->parent_bssid)))
10432 		goto nla_put_failure;
10433 
10434 	if (intbss->ts_boottime &&
10435 	    nla_put_u64_64bit(msg, NL80211_BSS_LAST_SEEN_BOOTTIME,
10436 			      intbss->ts_boottime, NL80211_BSS_PAD))
10437 		goto nla_put_failure;
10438 
10439 	if (!nl80211_put_signal(msg, intbss->pub.chains,
10440 				intbss->pub.chain_signal,
10441 				NL80211_BSS_CHAIN_SIGNAL))
10442 		goto nla_put_failure;
10443 
10444 	switch (rdev->wiphy.signal_type) {
10445 	case CFG80211_SIGNAL_TYPE_MBM:
10446 		if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
10447 			goto nla_put_failure;
10448 		break;
10449 	case CFG80211_SIGNAL_TYPE_UNSPEC:
10450 		if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
10451 			goto nla_put_failure;
10452 		break;
10453 	default:
10454 		break;
10455 	}
10456 
10457 	switch (wdev->iftype) {
10458 	case NL80211_IFTYPE_P2P_CLIENT:
10459 	case NL80211_IFTYPE_STATION:
10460 		for_each_valid_link(wdev, link_id) {
10461 			if (intbss == wdev->links[link_id].client.current_bss &&
10462 			    (nla_put_u32(msg, NL80211_BSS_STATUS,
10463 					 NL80211_BSS_STATUS_ASSOCIATED) ||
10464 			     (wdev->valid_links &&
10465 			      (nla_put_u8(msg, NL80211_BSS_MLO_LINK_ID,
10466 					  link_id) ||
10467 			       nla_put(msg, NL80211_BSS_MLD_ADDR, ETH_ALEN,
10468 				       wdev->u.client.connected_addr)))))
10469 				goto nla_put_failure;
10470 		}
10471 		break;
10472 	case NL80211_IFTYPE_ADHOC:
10473 		if (intbss == wdev->u.ibss.current_bss &&
10474 		    nla_put_u32(msg, NL80211_BSS_STATUS,
10475 				NL80211_BSS_STATUS_IBSS_JOINED))
10476 			goto nla_put_failure;
10477 		break;
10478 	default:
10479 		break;
10480 	}
10481 
10482 	nla_nest_end(msg, bss);
10483 
10484 	genlmsg_end(msg, hdr);
10485 	return 0;
10486 
10487  fail_unlock_rcu:
10488 	rcu_read_unlock();
10489  nla_put_failure:
10490 	genlmsg_cancel(msg, hdr);
10491 	return -EMSGSIZE;
10492 }
10493 
nl80211_dump_scan(struct sk_buff * skb,struct netlink_callback * cb)10494 static int nl80211_dump_scan(struct sk_buff *skb, struct netlink_callback *cb)
10495 {
10496 	struct cfg80211_registered_device *rdev;
10497 	struct cfg80211_internal_bss *scan;
10498 	struct wireless_dev *wdev;
10499 	int start = cb->args[2], idx = 0;
10500 	int err;
10501 
10502 	err = nl80211_prepare_wdev_dump(cb, &rdev, &wdev, NULL);
10503 	if (err)
10504 		return err;
10505 	/* nl80211_prepare_wdev_dump acquired it in the successful case */
10506 	__acquire(&rdev->wiphy.mtx);
10507 
10508 	wdev_lock(wdev);
10509 	spin_lock_bh(&rdev->bss_lock);
10510 
10511 	/*
10512 	 * dump_scan will be called multiple times to break up the scan results
10513 	 * into multiple messages.  It is unlikely that any more bss-es will be
10514 	 * expired after the first call, so only call only call this on the
10515 	 * first dump_scan invocation.
10516 	 */
10517 	if (start == 0)
10518 		cfg80211_bss_expire(rdev);
10519 
10520 	cb->seq = rdev->bss_generation;
10521 
10522 	list_for_each_entry(scan, &rdev->bss_list, list) {
10523 		if (++idx <= start)
10524 			continue;
10525 		if (nl80211_send_bss(skb, cb,
10526 				cb->nlh->nlmsg_seq, NLM_F_MULTI,
10527 				rdev, wdev, scan) < 0) {
10528 			idx--;
10529 			break;
10530 		}
10531 	}
10532 
10533 	spin_unlock_bh(&rdev->bss_lock);
10534 	wdev_unlock(wdev);
10535 
10536 	cb->args[2] = idx;
10537 	wiphy_unlock(&rdev->wiphy);
10538 
10539 	return skb->len;
10540 }
10541 
nl80211_send_survey(struct sk_buff * msg,u32 portid,u32 seq,int flags,struct net_device * dev,bool allow_radio_stats,struct survey_info * survey)10542 static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
10543 			       int flags, struct net_device *dev,
10544 			       bool allow_radio_stats,
10545 			       struct survey_info *survey)
10546 {
10547 	void *hdr;
10548 	struct nlattr *infoattr;
10549 
10550 	/* skip radio stats if userspace didn't request them */
10551 	if (!survey->channel && !allow_radio_stats)
10552 		return 0;
10553 
10554 	hdr = nl80211hdr_put(msg, portid, seq, flags,
10555 			     NL80211_CMD_NEW_SURVEY_RESULTS);
10556 	if (!hdr)
10557 		return -ENOMEM;
10558 
10559 	if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
10560 		goto nla_put_failure;
10561 
10562 	infoattr = nla_nest_start_noflag(msg, NL80211_ATTR_SURVEY_INFO);
10563 	if (!infoattr)
10564 		goto nla_put_failure;
10565 
10566 	if (survey->channel &&
10567 	    nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
10568 			survey->channel->center_freq))
10569 		goto nla_put_failure;
10570 
10571 	if (survey->channel && survey->channel->freq_offset &&
10572 	    nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY_OFFSET,
10573 			survey->channel->freq_offset))
10574 		goto nla_put_failure;
10575 
10576 	if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
10577 	    nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
10578 		goto nla_put_failure;
10579 	if ((survey->filled & SURVEY_INFO_IN_USE) &&
10580 	    nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
10581 		goto nla_put_failure;
10582 	if ((survey->filled & SURVEY_INFO_TIME) &&
10583 	    nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME,
10584 			survey->time, NL80211_SURVEY_INFO_PAD))
10585 		goto nla_put_failure;
10586 	if ((survey->filled & SURVEY_INFO_TIME_BUSY) &&
10587 	    nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_BUSY,
10588 			      survey->time_busy, NL80211_SURVEY_INFO_PAD))
10589 		goto nla_put_failure;
10590 	if ((survey->filled & SURVEY_INFO_TIME_EXT_BUSY) &&
10591 	    nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_EXT_BUSY,
10592 			      survey->time_ext_busy, NL80211_SURVEY_INFO_PAD))
10593 		goto nla_put_failure;
10594 	if ((survey->filled & SURVEY_INFO_TIME_RX) &&
10595 	    nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_RX,
10596 			      survey->time_rx, NL80211_SURVEY_INFO_PAD))
10597 		goto nla_put_failure;
10598 	if ((survey->filled & SURVEY_INFO_TIME_TX) &&
10599 	    nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_TX,
10600 			      survey->time_tx, NL80211_SURVEY_INFO_PAD))
10601 		goto nla_put_failure;
10602 	if ((survey->filled & SURVEY_INFO_TIME_SCAN) &&
10603 	    nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_SCAN,
10604 			      survey->time_scan, NL80211_SURVEY_INFO_PAD))
10605 		goto nla_put_failure;
10606 	if ((survey->filled & SURVEY_INFO_TIME_BSS_RX) &&
10607 	    nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_BSS_RX,
10608 			      survey->time_bss_rx, NL80211_SURVEY_INFO_PAD))
10609 		goto nla_put_failure;
10610 
10611 	nla_nest_end(msg, infoattr);
10612 
10613 	genlmsg_end(msg, hdr);
10614 	return 0;
10615 
10616  nla_put_failure:
10617 	genlmsg_cancel(msg, hdr);
10618 	return -EMSGSIZE;
10619 }
10620 
nl80211_dump_survey(struct sk_buff * skb,struct netlink_callback * cb)10621 static int nl80211_dump_survey(struct sk_buff *skb, struct netlink_callback *cb)
10622 {
10623 	struct nlattr **attrbuf;
10624 	struct survey_info survey;
10625 	struct cfg80211_registered_device *rdev;
10626 	struct wireless_dev *wdev;
10627 	int survey_idx = cb->args[2];
10628 	int res;
10629 	bool radio_stats;
10630 
10631 	attrbuf = kcalloc(NUM_NL80211_ATTR, sizeof(*attrbuf), GFP_KERNEL);
10632 	if (!attrbuf)
10633 		return -ENOMEM;
10634 
10635 	res = nl80211_prepare_wdev_dump(cb, &rdev, &wdev, attrbuf);
10636 	if (res) {
10637 		kfree(attrbuf);
10638 		return res;
10639 	}
10640 	/* nl80211_prepare_wdev_dump acquired it in the successful case */
10641 	__acquire(&rdev->wiphy.mtx);
10642 
10643 	/* prepare_wdev_dump parsed the attributes */
10644 	radio_stats = attrbuf[NL80211_ATTR_SURVEY_RADIO_STATS];
10645 
10646 	if (!wdev->netdev) {
10647 		res = -EINVAL;
10648 		goto out_err;
10649 	}
10650 
10651 	if (!rdev->ops->dump_survey) {
10652 		res = -EOPNOTSUPP;
10653 		goto out_err;
10654 	}
10655 
10656 	while (1) {
10657 		wdev_lock(wdev);
10658 		res = rdev_dump_survey(rdev, wdev->netdev, survey_idx, &survey);
10659 		wdev_unlock(wdev);
10660 		if (res == -ENOENT)
10661 			break;
10662 		if (res)
10663 			goto out_err;
10664 
10665 		/* don't send disabled channels, but do send non-channel data */
10666 		if (survey.channel &&
10667 		    survey.channel->flags & IEEE80211_CHAN_DISABLED) {
10668 			survey_idx++;
10669 			continue;
10670 		}
10671 
10672 		if (nl80211_send_survey(skb,
10673 				NETLINK_CB(cb->skb).portid,
10674 				cb->nlh->nlmsg_seq, NLM_F_MULTI,
10675 				wdev->netdev, radio_stats, &survey) < 0)
10676 			goto out;
10677 		survey_idx++;
10678 	}
10679 
10680  out:
10681 	cb->args[2] = survey_idx;
10682 	res = skb->len;
10683  out_err:
10684 	kfree(attrbuf);
10685 	wiphy_unlock(&rdev->wiphy);
10686 	return res;
10687 }
10688 
nl80211_valid_wpa_versions(u32 wpa_versions)10689 static bool nl80211_valid_wpa_versions(u32 wpa_versions)
10690 {
10691 	return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
10692 				  NL80211_WPA_VERSION_2 |
10693 				  NL80211_WPA_VERSION_3));
10694 }
10695 
nl80211_authenticate(struct sk_buff * skb,struct genl_info * info)10696 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
10697 {
10698 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
10699 	struct net_device *dev = info->user_ptr[1];
10700 	struct ieee80211_channel *chan;
10701 	const u8 *bssid, *ssid;
10702 	int err, ssid_len;
10703 	enum nl80211_auth_type auth_type;
10704 	struct key_parse key;
10705 	bool local_state_change;
10706 	struct cfg80211_auth_request req = {};
10707 	u32 freq;
10708 
10709 	if (!info->attrs[NL80211_ATTR_MAC])
10710 		return -EINVAL;
10711 
10712 	if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
10713 		return -EINVAL;
10714 
10715 	if (!info->attrs[NL80211_ATTR_SSID])
10716 		return -EINVAL;
10717 
10718 	if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
10719 		return -EINVAL;
10720 
10721 	err = nl80211_parse_key(info, &key);
10722 	if (err)
10723 		return err;
10724 
10725 	if (key.idx >= 0) {
10726 		if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
10727 			return -EINVAL;
10728 		if (!key.p.key || !key.p.key_len)
10729 			return -EINVAL;
10730 		if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
10731 		     key.p.key_len != WLAN_KEY_LEN_WEP40) &&
10732 		    (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
10733 		     key.p.key_len != WLAN_KEY_LEN_WEP104))
10734 			return -EINVAL;
10735 		if (key.idx > 3)
10736 			return -EINVAL;
10737 	} else {
10738 		key.p.key_len = 0;
10739 		key.p.key = NULL;
10740 	}
10741 
10742 	if (key.idx >= 0) {
10743 		int i;
10744 		bool ok = false;
10745 
10746 		for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
10747 			if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
10748 				ok = true;
10749 				break;
10750 			}
10751 		}
10752 		if (!ok)
10753 			return -EINVAL;
10754 	}
10755 
10756 	if (!rdev->ops->auth)
10757 		return -EOPNOTSUPP;
10758 
10759 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
10760 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
10761 		return -EOPNOTSUPP;
10762 
10763 	bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
10764 	freq = MHZ_TO_KHZ(nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
10765 	if (info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET])
10766 		freq +=
10767 		    nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET]);
10768 
10769 	chan = nl80211_get_valid_chan(&rdev->wiphy, freq);
10770 	if (!chan)
10771 		return -EINVAL;
10772 
10773 	ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
10774 	ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
10775 
10776 	if (info->attrs[NL80211_ATTR_IE]) {
10777 		req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
10778 		req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
10779 	}
10780 
10781 	auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
10782 	if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
10783 		return -EINVAL;
10784 
10785 	if ((auth_type == NL80211_AUTHTYPE_SAE ||
10786 	     auth_type == NL80211_AUTHTYPE_FILS_SK ||
10787 	     auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
10788 	     auth_type == NL80211_AUTHTYPE_FILS_PK) &&
10789 	    !info->attrs[NL80211_ATTR_AUTH_DATA])
10790 		return -EINVAL;
10791 
10792 	if (info->attrs[NL80211_ATTR_AUTH_DATA]) {
10793 		if (auth_type != NL80211_AUTHTYPE_SAE &&
10794 		    auth_type != NL80211_AUTHTYPE_FILS_SK &&
10795 		    auth_type != NL80211_AUTHTYPE_FILS_SK_PFS &&
10796 		    auth_type != NL80211_AUTHTYPE_FILS_PK)
10797 			return -EINVAL;
10798 		req.auth_data = nla_data(info->attrs[NL80211_ATTR_AUTH_DATA]);
10799 		req.auth_data_len = nla_len(info->attrs[NL80211_ATTR_AUTH_DATA]);
10800 	}
10801 
10802 	local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
10803 
10804 	/*
10805 	 * Since we no longer track auth state, ignore
10806 	 * requests to only change local state.
10807 	 */
10808 	if (local_state_change)
10809 		return 0;
10810 
10811 	req.auth_type = auth_type;
10812 	req.key = key.p.key;
10813 	req.key_len = key.p.key_len;
10814 	req.key_idx = key.idx;
10815 	req.link_id = nl80211_link_id_or_invalid(info->attrs);
10816 	if (req.link_id >= 0) {
10817 		if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_MLO))
10818 			return -EINVAL;
10819 		if (!info->attrs[NL80211_ATTR_MLD_ADDR])
10820 			return -EINVAL;
10821 		req.ap_mld_addr = nla_data(info->attrs[NL80211_ATTR_MLD_ADDR]);
10822 		if (!is_valid_ether_addr(req.ap_mld_addr))
10823 			return -EINVAL;
10824 	}
10825 
10826 	req.bss = cfg80211_get_bss(&rdev->wiphy, chan, bssid, ssid, ssid_len,
10827 				   IEEE80211_BSS_TYPE_ESS,
10828 				   IEEE80211_PRIVACY_ANY);
10829 	if (!req.bss)
10830 		return -ENOENT;
10831 
10832 	wdev_lock(dev->ieee80211_ptr);
10833 	err = cfg80211_mlme_auth(rdev, dev, &req);
10834 	wdev_unlock(dev->ieee80211_ptr);
10835 
10836 	cfg80211_put_bss(&rdev->wiphy, req.bss);
10837 
10838 	return err;
10839 }
10840 
validate_pae_over_nl80211(struct cfg80211_registered_device * rdev,struct genl_info * info)10841 static int validate_pae_over_nl80211(struct cfg80211_registered_device *rdev,
10842 				     struct genl_info *info)
10843 {
10844 	if (!info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
10845 		GENL_SET_ERR_MSG(info, "SOCKET_OWNER not set");
10846 		return -EINVAL;
10847 	}
10848 
10849 	if (!rdev->ops->tx_control_port ||
10850 	    !wiphy_ext_feature_isset(&rdev->wiphy,
10851 				     NL80211_EXT_FEATURE_CONTROL_PORT_OVER_NL80211))
10852 		return -EOPNOTSUPP;
10853 
10854 	return 0;
10855 }
10856 
nl80211_crypto_settings(struct cfg80211_registered_device * rdev,struct genl_info * info,struct cfg80211_crypto_settings * settings,int cipher_limit)10857 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
10858 				   struct genl_info *info,
10859 				   struct cfg80211_crypto_settings *settings,
10860 				   int cipher_limit)
10861 {
10862 	memset(settings, 0, sizeof(*settings));
10863 
10864 	settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
10865 
10866 	if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
10867 		u16 proto;
10868 
10869 		proto = nla_get_u16(
10870 			info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
10871 		settings->control_port_ethertype = cpu_to_be16(proto);
10872 		if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
10873 		    proto != ETH_P_PAE)
10874 			return -EINVAL;
10875 		if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
10876 			settings->control_port_no_encrypt = true;
10877 	} else
10878 		settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
10879 
10880 	if (info->attrs[NL80211_ATTR_CONTROL_PORT_OVER_NL80211]) {
10881 		int r = validate_pae_over_nl80211(rdev, info);
10882 
10883 		if (r < 0)
10884 			return r;
10885 
10886 		settings->control_port_over_nl80211 = true;
10887 
10888 		if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_PREAUTH])
10889 			settings->control_port_no_preauth = true;
10890 	}
10891 
10892 	if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
10893 		void *data;
10894 		int len, i;
10895 
10896 		data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
10897 		len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
10898 		settings->n_ciphers_pairwise = len / sizeof(u32);
10899 
10900 		if (len % sizeof(u32))
10901 			return -EINVAL;
10902 
10903 		if (settings->n_ciphers_pairwise > cipher_limit)
10904 			return -EINVAL;
10905 
10906 		memcpy(settings->ciphers_pairwise, data, len);
10907 
10908 		for (i = 0; i < settings->n_ciphers_pairwise; i++)
10909 			if (!cfg80211_supported_cipher_suite(
10910 					&rdev->wiphy,
10911 					settings->ciphers_pairwise[i]))
10912 				return -EINVAL;
10913 	}
10914 
10915 	if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
10916 		settings->cipher_group =
10917 			nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
10918 		if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
10919 						     settings->cipher_group))
10920 			return -EINVAL;
10921 	}
10922 
10923 	if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
10924 		settings->wpa_versions =
10925 			nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
10926 		if (!nl80211_valid_wpa_versions(settings->wpa_versions))
10927 			return -EINVAL;
10928 	}
10929 
10930 	if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
10931 		void *data;
10932 		int len;
10933 
10934 		data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
10935 		len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
10936 		settings->n_akm_suites = len / sizeof(u32);
10937 
10938 		if (len % sizeof(u32))
10939 			return -EINVAL;
10940 
10941 		if (settings->n_akm_suites > rdev->wiphy.max_num_akm_suites)
10942 			return -EINVAL;
10943 
10944 		memcpy(settings->akm_suites, data, len);
10945 	}
10946 
10947 	if (info->attrs[NL80211_ATTR_PMK]) {
10948 		if (nla_len(info->attrs[NL80211_ATTR_PMK]) != WLAN_PMK_LEN)
10949 			return -EINVAL;
10950 		if (!wiphy_ext_feature_isset(&rdev->wiphy,
10951 					     NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_PSK) &&
10952 		    !wiphy_ext_feature_isset(&rdev->wiphy,
10953 					     NL80211_EXT_FEATURE_4WAY_HANDSHAKE_AP_PSK))
10954 			return -EINVAL;
10955 		settings->psk = nla_data(info->attrs[NL80211_ATTR_PMK]);
10956 	}
10957 
10958 	if (info->attrs[NL80211_ATTR_SAE_PASSWORD]) {
10959 		if (!wiphy_ext_feature_isset(&rdev->wiphy,
10960 					     NL80211_EXT_FEATURE_SAE_OFFLOAD) &&
10961 		    !wiphy_ext_feature_isset(&rdev->wiphy,
10962 					     NL80211_EXT_FEATURE_SAE_OFFLOAD_AP))
10963 			return -EINVAL;
10964 		settings->sae_pwd =
10965 			nla_data(info->attrs[NL80211_ATTR_SAE_PASSWORD]);
10966 		settings->sae_pwd_len =
10967 			nla_len(info->attrs[NL80211_ATTR_SAE_PASSWORD]);
10968 	}
10969 
10970 	if (info->attrs[NL80211_ATTR_SAE_PWE])
10971 		settings->sae_pwe =
10972 			nla_get_u8(info->attrs[NL80211_ATTR_SAE_PWE]);
10973 	else
10974 		settings->sae_pwe = NL80211_SAE_PWE_UNSPECIFIED;
10975 
10976 	return 0;
10977 }
10978 
nl80211_assoc_bss(struct cfg80211_registered_device * rdev,const u8 * ssid,int ssid_len,struct nlattr ** attrs)10979 static struct cfg80211_bss *nl80211_assoc_bss(struct cfg80211_registered_device *rdev,
10980 					      const u8 *ssid, int ssid_len,
10981 					      struct nlattr **attrs)
10982 {
10983 	struct ieee80211_channel *chan;
10984 	struct cfg80211_bss *bss;
10985 	const u8 *bssid;
10986 	u32 freq;
10987 
10988 	if (!attrs[NL80211_ATTR_MAC] || !attrs[NL80211_ATTR_WIPHY_FREQ])
10989 		return ERR_PTR(-EINVAL);
10990 
10991 	bssid = nla_data(attrs[NL80211_ATTR_MAC]);
10992 
10993 	freq = MHZ_TO_KHZ(nla_get_u32(attrs[NL80211_ATTR_WIPHY_FREQ]));
10994 	if (attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET])
10995 		freq += nla_get_u32(attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET]);
10996 
10997 	chan = nl80211_get_valid_chan(&rdev->wiphy, freq);
10998 	if (!chan)
10999 		return ERR_PTR(-EINVAL);
11000 
11001 	bss = cfg80211_get_bss(&rdev->wiphy, chan, bssid,
11002 			       ssid, ssid_len,
11003 			       IEEE80211_BSS_TYPE_ESS,
11004 			       IEEE80211_PRIVACY_ANY);
11005 	if (!bss)
11006 		return ERR_PTR(-ENOENT);
11007 
11008 	return bss;
11009 }
11010 
nl80211_associate(struct sk_buff * skb,struct genl_info * info)11011 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
11012 {
11013 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
11014 	struct net_device *dev = info->user_ptr[1];
11015 	struct cfg80211_assoc_request req = {};
11016 	struct nlattr **attrs = NULL;
11017 	const u8 *ap_addr, *ssid;
11018 	unsigned int link_id;
11019 	int err, ssid_len;
11020 
11021 	if (dev->ieee80211_ptr->conn_owner_nlportid &&
11022 	    dev->ieee80211_ptr->conn_owner_nlportid != info->snd_portid)
11023 		return -EPERM;
11024 
11025 	if (!info->attrs[NL80211_ATTR_SSID])
11026 		return -EINVAL;
11027 
11028 	if (!rdev->ops->assoc)
11029 		return -EOPNOTSUPP;
11030 
11031 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
11032 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
11033 		return -EOPNOTSUPP;
11034 
11035 	ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
11036 	ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
11037 
11038 	if (info->attrs[NL80211_ATTR_IE]) {
11039 		req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
11040 		req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
11041 
11042 		if (cfg80211_find_ext_elem(WLAN_EID_EXT_NON_INHERITANCE,
11043 					   req.ie, req.ie_len)) {
11044 			GENL_SET_ERR_MSG(info,
11045 					 "non-inheritance makes no sense");
11046 			return -EINVAL;
11047 		}
11048 	}
11049 
11050 	if (info->attrs[NL80211_ATTR_USE_MFP]) {
11051 		enum nl80211_mfp mfp =
11052 			nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
11053 		if (mfp == NL80211_MFP_REQUIRED)
11054 			req.use_mfp = true;
11055 		else if (mfp != NL80211_MFP_NO)
11056 			return -EINVAL;
11057 	}
11058 
11059 	if (info->attrs[NL80211_ATTR_PREV_BSSID])
11060 		req.prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
11061 
11062 	if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
11063 		req.flags |= ASSOC_REQ_DISABLE_HT;
11064 
11065 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
11066 		memcpy(&req.ht_capa_mask,
11067 		       nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
11068 		       sizeof(req.ht_capa_mask));
11069 
11070 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
11071 		if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
11072 			return -EINVAL;
11073 		memcpy(&req.ht_capa,
11074 		       nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
11075 		       sizeof(req.ht_capa));
11076 	}
11077 
11078 	if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
11079 		req.flags |= ASSOC_REQ_DISABLE_VHT;
11080 
11081 	if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HE]))
11082 		req.flags |= ASSOC_REQ_DISABLE_HE;
11083 
11084 	if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_EHT]))
11085 		req.flags |= ASSOC_REQ_DISABLE_EHT;
11086 
11087 	if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
11088 		memcpy(&req.vht_capa_mask,
11089 		       nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
11090 		       sizeof(req.vht_capa_mask));
11091 
11092 	if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
11093 		if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
11094 			return -EINVAL;
11095 		memcpy(&req.vht_capa,
11096 		       nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
11097 		       sizeof(req.vht_capa));
11098 	}
11099 
11100 	if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) {
11101 		if (!((rdev->wiphy.features &
11102 			NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) &&
11103 		       (rdev->wiphy.features & NL80211_FEATURE_QUIET)) &&
11104 		    !wiphy_ext_feature_isset(&rdev->wiphy,
11105 					     NL80211_EXT_FEATURE_RRM))
11106 			return -EINVAL;
11107 		req.flags |= ASSOC_REQ_USE_RRM;
11108 	}
11109 
11110 	if (info->attrs[NL80211_ATTR_FILS_KEK]) {
11111 		req.fils_kek = nla_data(info->attrs[NL80211_ATTR_FILS_KEK]);
11112 		req.fils_kek_len = nla_len(info->attrs[NL80211_ATTR_FILS_KEK]);
11113 		if (!info->attrs[NL80211_ATTR_FILS_NONCES])
11114 			return -EINVAL;
11115 		req.fils_nonces =
11116 			nla_data(info->attrs[NL80211_ATTR_FILS_NONCES]);
11117 	}
11118 
11119 	if (info->attrs[NL80211_ATTR_S1G_CAPABILITY_MASK]) {
11120 		if (!info->attrs[NL80211_ATTR_S1G_CAPABILITY])
11121 			return -EINVAL;
11122 		memcpy(&req.s1g_capa_mask,
11123 		       nla_data(info->attrs[NL80211_ATTR_S1G_CAPABILITY_MASK]),
11124 		       sizeof(req.s1g_capa_mask));
11125 	}
11126 
11127 	if (info->attrs[NL80211_ATTR_S1G_CAPABILITY]) {
11128 		if (!info->attrs[NL80211_ATTR_S1G_CAPABILITY_MASK])
11129 			return -EINVAL;
11130 		memcpy(&req.s1g_capa,
11131 		       nla_data(info->attrs[NL80211_ATTR_S1G_CAPABILITY]),
11132 		       sizeof(req.s1g_capa));
11133 	}
11134 
11135 	req.link_id = nl80211_link_id_or_invalid(info->attrs);
11136 
11137 	if (info->attrs[NL80211_ATTR_MLO_LINKS]) {
11138 		unsigned int attrsize = NUM_NL80211_ATTR * sizeof(*attrs);
11139 		struct nlattr *link;
11140 		int rem = 0;
11141 
11142 		if (req.link_id < 0)
11143 			return -EINVAL;
11144 
11145 		if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_MLO))
11146 			return -EINVAL;
11147 
11148 		if (info->attrs[NL80211_ATTR_MAC] ||
11149 		    info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
11150 		    !info->attrs[NL80211_ATTR_MLD_ADDR])
11151 			return -EINVAL;
11152 
11153 		req.ap_mld_addr = nla_data(info->attrs[NL80211_ATTR_MLD_ADDR]);
11154 		ap_addr = req.ap_mld_addr;
11155 
11156 		attrs = kzalloc(attrsize, GFP_KERNEL);
11157 		if (!attrs)
11158 			return -ENOMEM;
11159 
11160 		nla_for_each_nested(link,
11161 				    info->attrs[NL80211_ATTR_MLO_LINKS],
11162 				    rem) {
11163 			memset(attrs, 0, attrsize);
11164 
11165 			nla_parse_nested(attrs, NL80211_ATTR_MAX,
11166 					 link, NULL, NULL);
11167 
11168 			if (!attrs[NL80211_ATTR_MLO_LINK_ID]) {
11169 				err = -EINVAL;
11170 				goto free;
11171 			}
11172 
11173 			link_id = nla_get_u8(attrs[NL80211_ATTR_MLO_LINK_ID]);
11174 			/* cannot use the same link ID again */
11175 			if (req.links[link_id].bss) {
11176 				err = -EINVAL;
11177 				goto free;
11178 			}
11179 			req.links[link_id].bss =
11180 				nl80211_assoc_bss(rdev, ssid, ssid_len, attrs);
11181 			if (IS_ERR(req.links[link_id].bss)) {
11182 				err = PTR_ERR(req.links[link_id].bss);
11183 				req.links[link_id].bss = NULL;
11184 				goto free;
11185 			}
11186 
11187 			if (attrs[NL80211_ATTR_IE]) {
11188 				req.links[link_id].elems =
11189 					nla_data(attrs[NL80211_ATTR_IE]);
11190 				req.links[link_id].elems_len =
11191 					nla_len(attrs[NL80211_ATTR_IE]);
11192 
11193 				if (cfg80211_find_elem(WLAN_EID_FRAGMENT,
11194 						       req.links[link_id].elems,
11195 						       req.links[link_id].elems_len)) {
11196 					GENL_SET_ERR_MSG(info,
11197 							 "cannot deal with fragmentation");
11198 					err = -EINVAL;
11199 					goto free;
11200 				}
11201 
11202 				if (cfg80211_find_ext_elem(WLAN_EID_EXT_NON_INHERITANCE,
11203 							   req.links[link_id].elems,
11204 							   req.links[link_id].elems_len)) {
11205 					GENL_SET_ERR_MSG(info,
11206 							 "cannot deal with non-inheritance");
11207 					err = -EINVAL;
11208 					goto free;
11209 				}
11210 			}
11211 
11212 			req.links[link_id].disabled =
11213 				nla_get_flag(attrs[NL80211_ATTR_MLO_LINK_DISABLED]);
11214 		}
11215 
11216 		if (!req.links[req.link_id].bss) {
11217 			err = -EINVAL;
11218 			goto free;
11219 		}
11220 
11221 		if (req.links[req.link_id].elems_len) {
11222 			GENL_SET_ERR_MSG(info,
11223 					 "cannot have per-link elems on assoc link");
11224 			err = -EINVAL;
11225 			goto free;
11226 		}
11227 
11228 		if (req.links[req.link_id].disabled) {
11229 			GENL_SET_ERR_MSG(info,
11230 					 "cannot have assoc link disabled");
11231 			err = -EINVAL;
11232 			goto free;
11233 		}
11234 
11235 		kfree(attrs);
11236 		attrs = NULL;
11237 	} else {
11238 		if (req.link_id >= 0)
11239 			return -EINVAL;
11240 
11241 		req.bss = nl80211_assoc_bss(rdev, ssid, ssid_len, info->attrs);
11242 		if (IS_ERR(req.bss))
11243 			return PTR_ERR(req.bss);
11244 		ap_addr = req.bss->bssid;
11245 	}
11246 
11247 	err = nl80211_crypto_settings(rdev, info, &req.crypto, 1);
11248 	if (!err) {
11249 		wdev_lock(dev->ieee80211_ptr);
11250 
11251 		err = cfg80211_mlme_assoc(rdev, dev, &req);
11252 
11253 		if (!err && info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
11254 			dev->ieee80211_ptr->conn_owner_nlportid =
11255 				info->snd_portid;
11256 			memcpy(dev->ieee80211_ptr->disconnect_bssid,
11257 			       ap_addr, ETH_ALEN);
11258 		}
11259 
11260 		wdev_unlock(dev->ieee80211_ptr);
11261 	}
11262 
11263 free:
11264 	for (link_id = 0; link_id < ARRAY_SIZE(req.links); link_id++)
11265 		cfg80211_put_bss(&rdev->wiphy, req.links[link_id].bss);
11266 	cfg80211_put_bss(&rdev->wiphy, req.bss);
11267 	kfree(attrs);
11268 
11269 	return err;
11270 }
11271 
nl80211_deauthenticate(struct sk_buff * skb,struct genl_info * info)11272 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
11273 {
11274 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
11275 	struct net_device *dev = info->user_ptr[1];
11276 	const u8 *ie = NULL, *bssid;
11277 	int ie_len = 0, err;
11278 	u16 reason_code;
11279 	bool local_state_change;
11280 
11281 	if (dev->ieee80211_ptr->conn_owner_nlportid &&
11282 	    dev->ieee80211_ptr->conn_owner_nlportid != info->snd_portid)
11283 		return -EPERM;
11284 
11285 	if (!info->attrs[NL80211_ATTR_MAC])
11286 		return -EINVAL;
11287 
11288 	if (!info->attrs[NL80211_ATTR_REASON_CODE])
11289 		return -EINVAL;
11290 
11291 	if (!rdev->ops->deauth)
11292 		return -EOPNOTSUPP;
11293 
11294 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
11295 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
11296 		return -EOPNOTSUPP;
11297 
11298 	bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
11299 
11300 	reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
11301 	if (reason_code == 0) {
11302 		/* Reason Code 0 is reserved */
11303 		return -EINVAL;
11304 	}
11305 
11306 	if (info->attrs[NL80211_ATTR_IE]) {
11307 		ie = nla_data(info->attrs[NL80211_ATTR_IE]);
11308 		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
11309 	}
11310 
11311 	local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
11312 
11313 	wdev_lock(dev->ieee80211_ptr);
11314 	err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
11315 				   local_state_change);
11316 	wdev_unlock(dev->ieee80211_ptr);
11317 	return err;
11318 }
11319 
nl80211_disassociate(struct sk_buff * skb,struct genl_info * info)11320 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
11321 {
11322 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
11323 	struct net_device *dev = info->user_ptr[1];
11324 	const u8 *ie = NULL, *bssid;
11325 	int ie_len = 0, err;
11326 	u16 reason_code;
11327 	bool local_state_change;
11328 
11329 	if (dev->ieee80211_ptr->conn_owner_nlportid &&
11330 	    dev->ieee80211_ptr->conn_owner_nlportid != info->snd_portid)
11331 		return -EPERM;
11332 
11333 	if (!info->attrs[NL80211_ATTR_MAC])
11334 		return -EINVAL;
11335 
11336 	if (!info->attrs[NL80211_ATTR_REASON_CODE])
11337 		return -EINVAL;
11338 
11339 	if (!rdev->ops->disassoc)
11340 		return -EOPNOTSUPP;
11341 
11342 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
11343 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
11344 		return -EOPNOTSUPP;
11345 
11346 	bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
11347 
11348 	reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
11349 	if (reason_code == 0) {
11350 		/* Reason Code 0 is reserved */
11351 		return -EINVAL;
11352 	}
11353 
11354 	if (info->attrs[NL80211_ATTR_IE]) {
11355 		ie = nla_data(info->attrs[NL80211_ATTR_IE]);
11356 		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
11357 	}
11358 
11359 	local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
11360 
11361 	wdev_lock(dev->ieee80211_ptr);
11362 	err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
11363 				     local_state_change);
11364 	wdev_unlock(dev->ieee80211_ptr);
11365 	return err;
11366 }
11367 
11368 static bool
nl80211_parse_mcast_rate(struct cfg80211_registered_device * rdev,int mcast_rate[NUM_NL80211_BANDS],int rateval)11369 nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
11370 			 int mcast_rate[NUM_NL80211_BANDS],
11371 			 int rateval)
11372 {
11373 	struct wiphy *wiphy = &rdev->wiphy;
11374 	bool found = false;
11375 	int band, i;
11376 
11377 	for (band = 0; band < NUM_NL80211_BANDS; band++) {
11378 		struct ieee80211_supported_band *sband;
11379 
11380 		sband = wiphy->bands[band];
11381 		if (!sband)
11382 			continue;
11383 
11384 		for (i = 0; i < sband->n_bitrates; i++) {
11385 			if (sband->bitrates[i].bitrate == rateval) {
11386 				mcast_rate[band] = i + 1;
11387 				found = true;
11388 				break;
11389 			}
11390 		}
11391 	}
11392 
11393 	return found;
11394 }
11395 
nl80211_join_ibss(struct sk_buff * skb,struct genl_info * info)11396 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
11397 {
11398 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
11399 	struct net_device *dev = info->user_ptr[1];
11400 	struct cfg80211_ibss_params ibss;
11401 	struct wiphy *wiphy;
11402 	struct cfg80211_cached_keys *connkeys = NULL;
11403 	int err;
11404 
11405 	memset(&ibss, 0, sizeof(ibss));
11406 
11407 	if (!info->attrs[NL80211_ATTR_SSID] ||
11408 	    !nla_len(info->attrs[NL80211_ATTR_SSID]))
11409 		return -EINVAL;
11410 
11411 	ibss.beacon_interval = 100;
11412 
11413 	if (info->attrs[NL80211_ATTR_BEACON_INTERVAL])
11414 		ibss.beacon_interval =
11415 			nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
11416 
11417 	err = cfg80211_validate_beacon_int(rdev, NL80211_IFTYPE_ADHOC,
11418 					   ibss.beacon_interval);
11419 	if (err)
11420 		return err;
11421 
11422 	if (!rdev->ops->join_ibss)
11423 		return -EOPNOTSUPP;
11424 
11425 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
11426 		return -EOPNOTSUPP;
11427 
11428 	wiphy = &rdev->wiphy;
11429 
11430 	if (info->attrs[NL80211_ATTR_MAC]) {
11431 		ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
11432 
11433 		if (!is_valid_ether_addr(ibss.bssid))
11434 			return -EINVAL;
11435 	}
11436 	ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
11437 	ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
11438 
11439 	if (info->attrs[NL80211_ATTR_IE]) {
11440 		ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
11441 		ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
11442 	}
11443 
11444 	err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
11445 	if (err)
11446 		return err;
11447 
11448 	if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef,
11449 				     NL80211_IFTYPE_ADHOC))
11450 		return -EINVAL;
11451 
11452 	switch (ibss.chandef.width) {
11453 	case NL80211_CHAN_WIDTH_5:
11454 	case NL80211_CHAN_WIDTH_10:
11455 	case NL80211_CHAN_WIDTH_20_NOHT:
11456 		break;
11457 	case NL80211_CHAN_WIDTH_20:
11458 	case NL80211_CHAN_WIDTH_40:
11459 		if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
11460 			return -EINVAL;
11461 		break;
11462 	case NL80211_CHAN_WIDTH_80:
11463 	case NL80211_CHAN_WIDTH_80P80:
11464 	case NL80211_CHAN_WIDTH_160:
11465 		if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
11466 			return -EINVAL;
11467 		if (!wiphy_ext_feature_isset(&rdev->wiphy,
11468 					     NL80211_EXT_FEATURE_VHT_IBSS))
11469 			return -EINVAL;
11470 		break;
11471 	case NL80211_CHAN_WIDTH_320:
11472 		return -EINVAL;
11473 	default:
11474 		return -EINVAL;
11475 	}
11476 
11477 	ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
11478 	ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
11479 
11480 	if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
11481 		u8 *rates =
11482 			nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
11483 		int n_rates =
11484 			nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
11485 		struct ieee80211_supported_band *sband =
11486 			wiphy->bands[ibss.chandef.chan->band];
11487 
11488 		err = ieee80211_get_ratemask(sband, rates, n_rates,
11489 					     &ibss.basic_rates);
11490 		if (err)
11491 			return err;
11492 	}
11493 
11494 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
11495 		memcpy(&ibss.ht_capa_mask,
11496 		       nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
11497 		       sizeof(ibss.ht_capa_mask));
11498 
11499 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
11500 		if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
11501 			return -EINVAL;
11502 		memcpy(&ibss.ht_capa,
11503 		       nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
11504 		       sizeof(ibss.ht_capa));
11505 	}
11506 
11507 	if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
11508 	    !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
11509 			nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
11510 		return -EINVAL;
11511 
11512 	if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
11513 		bool no_ht = false;
11514 
11515 		connkeys = nl80211_parse_connkeys(rdev, info, &no_ht);
11516 		if (IS_ERR(connkeys))
11517 			return PTR_ERR(connkeys);
11518 
11519 		if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
11520 		    no_ht) {
11521 			kfree_sensitive(connkeys);
11522 			return -EINVAL;
11523 		}
11524 	}
11525 
11526 	ibss.control_port =
11527 		nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
11528 
11529 	if (info->attrs[NL80211_ATTR_CONTROL_PORT_OVER_NL80211]) {
11530 		int r = validate_pae_over_nl80211(rdev, info);
11531 
11532 		if (r < 0) {
11533 			kfree_sensitive(connkeys);
11534 			return r;
11535 		}
11536 
11537 		ibss.control_port_over_nl80211 = true;
11538 	}
11539 
11540 	ibss.userspace_handles_dfs =
11541 		nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]);
11542 
11543 	wdev_lock(dev->ieee80211_ptr);
11544 	err = __cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
11545 	if (err)
11546 		kfree_sensitive(connkeys);
11547 	else if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
11548 		dev->ieee80211_ptr->conn_owner_nlportid = info->snd_portid;
11549 	wdev_unlock(dev->ieee80211_ptr);
11550 
11551 	return err;
11552 }
11553 
nl80211_leave_ibss(struct sk_buff * skb,struct genl_info * info)11554 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
11555 {
11556 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
11557 	struct net_device *dev = info->user_ptr[1];
11558 
11559 	if (!rdev->ops->leave_ibss)
11560 		return -EOPNOTSUPP;
11561 
11562 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
11563 		return -EOPNOTSUPP;
11564 
11565 	return cfg80211_leave_ibss(rdev, dev, false);
11566 }
11567 
nl80211_set_mcast_rate(struct sk_buff * skb,struct genl_info * info)11568 static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
11569 {
11570 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
11571 	struct net_device *dev = info->user_ptr[1];
11572 	int mcast_rate[NUM_NL80211_BANDS];
11573 	u32 nla_rate;
11574 
11575 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
11576 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
11577 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_OCB)
11578 		return -EOPNOTSUPP;
11579 
11580 	if (!rdev->ops->set_mcast_rate)
11581 		return -EOPNOTSUPP;
11582 
11583 	memset(mcast_rate, 0, sizeof(mcast_rate));
11584 
11585 	if (!info->attrs[NL80211_ATTR_MCAST_RATE])
11586 		return -EINVAL;
11587 
11588 	nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
11589 	if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
11590 		return -EINVAL;
11591 
11592 	return rdev_set_mcast_rate(rdev, dev, mcast_rate);
11593 }
11594 
11595 static struct sk_buff *
__cfg80211_alloc_vendor_skb(struct cfg80211_registered_device * rdev,struct wireless_dev * wdev,int approxlen,u32 portid,u32 seq,enum nl80211_commands cmd,enum nl80211_attrs attr,const struct nl80211_vendor_cmd_info * info,gfp_t gfp)11596 __cfg80211_alloc_vendor_skb(struct cfg80211_registered_device *rdev,
11597 			    struct wireless_dev *wdev, int approxlen,
11598 			    u32 portid, u32 seq, enum nl80211_commands cmd,
11599 			    enum nl80211_attrs attr,
11600 			    const struct nl80211_vendor_cmd_info *info,
11601 			    gfp_t gfp)
11602 {
11603 	struct sk_buff *skb;
11604 	void *hdr;
11605 	struct nlattr *data;
11606 
11607 	skb = nlmsg_new(approxlen + 100, gfp);
11608 	if (!skb)
11609 		return NULL;
11610 
11611 	hdr = nl80211hdr_put(skb, portid, seq, 0, cmd);
11612 	if (!hdr) {
11613 		kfree_skb(skb);
11614 		return NULL;
11615 	}
11616 
11617 	if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
11618 		goto nla_put_failure;
11619 
11620 	if (info) {
11621 		if (nla_put_u32(skb, NL80211_ATTR_VENDOR_ID,
11622 				info->vendor_id))
11623 			goto nla_put_failure;
11624 		if (nla_put_u32(skb, NL80211_ATTR_VENDOR_SUBCMD,
11625 				info->subcmd))
11626 			goto nla_put_failure;
11627 	}
11628 
11629 	if (wdev) {
11630 		if (nla_put_u64_64bit(skb, NL80211_ATTR_WDEV,
11631 				      wdev_id(wdev), NL80211_ATTR_PAD))
11632 			goto nla_put_failure;
11633 		if (wdev->netdev &&
11634 		    nla_put_u32(skb, NL80211_ATTR_IFINDEX,
11635 				wdev->netdev->ifindex))
11636 			goto nla_put_failure;
11637 	}
11638 
11639 	data = nla_nest_start_noflag(skb, attr);
11640 	if (!data)
11641 		goto nla_put_failure;
11642 
11643 	((void **)skb->cb)[0] = rdev;
11644 	((void **)skb->cb)[1] = hdr;
11645 	((void **)skb->cb)[2] = data;
11646 
11647 	return skb;
11648 
11649  nla_put_failure:
11650 	kfree_skb(skb);
11651 	return NULL;
11652 }
11653 
__cfg80211_alloc_event_skb(struct wiphy * wiphy,struct wireless_dev * wdev,enum nl80211_commands cmd,enum nl80211_attrs attr,unsigned int portid,int vendor_event_idx,int approxlen,gfp_t gfp)11654 struct sk_buff *__cfg80211_alloc_event_skb(struct wiphy *wiphy,
11655 					   struct wireless_dev *wdev,
11656 					   enum nl80211_commands cmd,
11657 					   enum nl80211_attrs attr,
11658 					   unsigned int portid,
11659 					   int vendor_event_idx,
11660 					   int approxlen, gfp_t gfp)
11661 {
11662 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
11663 	const struct nl80211_vendor_cmd_info *info;
11664 
11665 	switch (cmd) {
11666 	case NL80211_CMD_TESTMODE:
11667 		if (WARN_ON(vendor_event_idx != -1))
11668 			return NULL;
11669 		info = NULL;
11670 		break;
11671 	case NL80211_CMD_VENDOR:
11672 		if (WARN_ON(vendor_event_idx < 0 ||
11673 			    vendor_event_idx >= wiphy->n_vendor_events))
11674 			return NULL;
11675 		info = &wiphy->vendor_events[vendor_event_idx];
11676 		break;
11677 	default:
11678 		WARN_ON(1);
11679 		return NULL;
11680 	}
11681 
11682 	return __cfg80211_alloc_vendor_skb(rdev, wdev, approxlen, portid, 0,
11683 					   cmd, attr, info, gfp);
11684 }
11685 EXPORT_SYMBOL(__cfg80211_alloc_event_skb);
11686 
__cfg80211_send_event_skb(struct sk_buff * skb,gfp_t gfp)11687 void __cfg80211_send_event_skb(struct sk_buff *skb, gfp_t gfp)
11688 {
11689 	struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
11690 	void *hdr = ((void **)skb->cb)[1];
11691 	struct nlmsghdr *nlhdr = nlmsg_hdr(skb);
11692 	struct nlattr *data = ((void **)skb->cb)[2];
11693 	enum nl80211_multicast_groups mcgrp = NL80211_MCGRP_TESTMODE;
11694 
11695 	/* clear CB data for netlink core to own from now on */
11696 	memset(skb->cb, 0, sizeof(skb->cb));
11697 
11698 	nla_nest_end(skb, data);
11699 	genlmsg_end(skb, hdr);
11700 
11701 	if (nlhdr->nlmsg_pid) {
11702 		genlmsg_unicast(wiphy_net(&rdev->wiphy), skb,
11703 				nlhdr->nlmsg_pid);
11704 	} else {
11705 		if (data->nla_type == NL80211_ATTR_VENDOR_DATA)
11706 			mcgrp = NL80211_MCGRP_VENDOR;
11707 
11708 		genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
11709 					skb, 0, mcgrp, gfp);
11710 	}
11711 }
11712 EXPORT_SYMBOL(__cfg80211_send_event_skb);
11713 
11714 #ifdef CONFIG_NL80211_TESTMODE
nl80211_testmode_do(struct sk_buff * skb,struct genl_info * info)11715 static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
11716 {
11717 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
11718 	struct wireless_dev *wdev;
11719 	int err;
11720 
11721 	lockdep_assert_held(&rdev->wiphy.mtx);
11722 
11723 	wdev = __cfg80211_wdev_from_attrs(rdev, genl_info_net(info),
11724 					  info->attrs);
11725 
11726 	if (!rdev->ops->testmode_cmd)
11727 		return -EOPNOTSUPP;
11728 
11729 	if (IS_ERR(wdev)) {
11730 		err = PTR_ERR(wdev);
11731 		if (err != -EINVAL)
11732 			return err;
11733 		wdev = NULL;
11734 	} else if (wdev->wiphy != &rdev->wiphy) {
11735 		return -EINVAL;
11736 	}
11737 
11738 	if (!info->attrs[NL80211_ATTR_TESTDATA])
11739 		return -EINVAL;
11740 
11741 	rdev->cur_cmd_info = info;
11742 	err = rdev_testmode_cmd(rdev, wdev,
11743 				nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
11744 				nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
11745 	rdev->cur_cmd_info = NULL;
11746 
11747 	return err;
11748 }
11749 
nl80211_testmode_dump(struct sk_buff * skb,struct netlink_callback * cb)11750 static int nl80211_testmode_dump(struct sk_buff *skb,
11751 				 struct netlink_callback *cb)
11752 {
11753 	struct cfg80211_registered_device *rdev;
11754 	struct nlattr **attrbuf = NULL;
11755 	int err;
11756 	long phy_idx;
11757 	void *data = NULL;
11758 	int data_len = 0;
11759 
11760 	rtnl_lock();
11761 
11762 	if (cb->args[0]) {
11763 		/*
11764 		 * 0 is a valid index, but not valid for args[0],
11765 		 * so we need to offset by 1.
11766 		 */
11767 		phy_idx = cb->args[0] - 1;
11768 
11769 		rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
11770 		if (!rdev) {
11771 			err = -ENOENT;
11772 			goto out_err;
11773 		}
11774 	} else {
11775 		attrbuf = kcalloc(NUM_NL80211_ATTR, sizeof(*attrbuf),
11776 				  GFP_KERNEL);
11777 		if (!attrbuf) {
11778 			err = -ENOMEM;
11779 			goto out_err;
11780 		}
11781 
11782 		err = nlmsg_parse_deprecated(cb->nlh,
11783 					     GENL_HDRLEN + nl80211_fam.hdrsize,
11784 					     attrbuf, nl80211_fam.maxattr,
11785 					     nl80211_policy, NULL);
11786 		if (err)
11787 			goto out_err;
11788 
11789 		rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf);
11790 		if (IS_ERR(rdev)) {
11791 			err = PTR_ERR(rdev);
11792 			goto out_err;
11793 		}
11794 		phy_idx = rdev->wiphy_idx;
11795 
11796 		if (attrbuf[NL80211_ATTR_TESTDATA])
11797 			cb->args[1] = (long)attrbuf[NL80211_ATTR_TESTDATA];
11798 	}
11799 
11800 	if (cb->args[1]) {
11801 		data = nla_data((void *)cb->args[1]);
11802 		data_len = nla_len((void *)cb->args[1]);
11803 	}
11804 
11805 	if (!rdev->ops->testmode_dump) {
11806 		err = -EOPNOTSUPP;
11807 		goto out_err;
11808 	}
11809 
11810 	while (1) {
11811 		void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
11812 					   cb->nlh->nlmsg_seq, NLM_F_MULTI,
11813 					   NL80211_CMD_TESTMODE);
11814 		struct nlattr *tmdata;
11815 
11816 		if (!hdr)
11817 			break;
11818 
11819 		if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
11820 			genlmsg_cancel(skb, hdr);
11821 			break;
11822 		}
11823 
11824 		tmdata = nla_nest_start_noflag(skb, NL80211_ATTR_TESTDATA);
11825 		if (!tmdata) {
11826 			genlmsg_cancel(skb, hdr);
11827 			break;
11828 		}
11829 		err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
11830 		nla_nest_end(skb, tmdata);
11831 
11832 		if (err == -ENOBUFS || err == -ENOENT) {
11833 			genlmsg_cancel(skb, hdr);
11834 			break;
11835 		} else if (err) {
11836 			genlmsg_cancel(skb, hdr);
11837 			goto out_err;
11838 		}
11839 
11840 		genlmsg_end(skb, hdr);
11841 	}
11842 
11843 	err = skb->len;
11844 	/* see above */
11845 	cb->args[0] = phy_idx + 1;
11846  out_err:
11847 	kfree(attrbuf);
11848 	rtnl_unlock();
11849 	return err;
11850 }
11851 #endif
11852 
nl80211_connect(struct sk_buff * skb,struct genl_info * info)11853 static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
11854 {
11855 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
11856 	struct net_device *dev = info->user_ptr[1];
11857 	struct cfg80211_connect_params connect;
11858 	struct wiphy *wiphy;
11859 	struct cfg80211_cached_keys *connkeys = NULL;
11860 	u32 freq = 0;
11861 	int err;
11862 
11863 	memset(&connect, 0, sizeof(connect));
11864 
11865 	if (!info->attrs[NL80211_ATTR_SSID] ||
11866 	    !nla_len(info->attrs[NL80211_ATTR_SSID]))
11867 		return -EINVAL;
11868 
11869 	if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
11870 		connect.auth_type =
11871 			nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
11872 		if (!nl80211_valid_auth_type(rdev, connect.auth_type,
11873 					     NL80211_CMD_CONNECT))
11874 			return -EINVAL;
11875 	} else
11876 		connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
11877 
11878 	connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
11879 
11880 	if (info->attrs[NL80211_ATTR_WANT_1X_4WAY_HS] &&
11881 	    !wiphy_ext_feature_isset(&rdev->wiphy,
11882 				     NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X))
11883 		return -EINVAL;
11884 	connect.want_1x = info->attrs[NL80211_ATTR_WANT_1X_4WAY_HS];
11885 
11886 	err = nl80211_crypto_settings(rdev, info, &connect.crypto,
11887 				      NL80211_MAX_NR_CIPHER_SUITES);
11888 	if (err)
11889 		return err;
11890 
11891 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
11892 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
11893 		return -EOPNOTSUPP;
11894 
11895 	wiphy = &rdev->wiphy;
11896 
11897 	connect.bg_scan_period = -1;
11898 	if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
11899 		(wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
11900 		connect.bg_scan_period =
11901 			nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
11902 	}
11903 
11904 	if (info->attrs[NL80211_ATTR_MAC])
11905 		connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
11906 	else if (info->attrs[NL80211_ATTR_MAC_HINT])
11907 		connect.bssid_hint =
11908 			nla_data(info->attrs[NL80211_ATTR_MAC_HINT]);
11909 	connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
11910 	connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
11911 
11912 	if (info->attrs[NL80211_ATTR_IE]) {
11913 		connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
11914 		connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
11915 	}
11916 
11917 	if (info->attrs[NL80211_ATTR_USE_MFP]) {
11918 		connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
11919 		if (connect.mfp == NL80211_MFP_OPTIONAL &&
11920 		    !wiphy_ext_feature_isset(&rdev->wiphy,
11921 					     NL80211_EXT_FEATURE_MFP_OPTIONAL))
11922 			return -EOPNOTSUPP;
11923 	} else {
11924 		connect.mfp = NL80211_MFP_NO;
11925 	}
11926 
11927 	if (info->attrs[NL80211_ATTR_PREV_BSSID])
11928 		connect.prev_bssid =
11929 			nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
11930 
11931 	if (info->attrs[NL80211_ATTR_WIPHY_FREQ])
11932 		freq = MHZ_TO_KHZ(nla_get_u32(
11933 					info->attrs[NL80211_ATTR_WIPHY_FREQ]));
11934 	if (info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET])
11935 		freq +=
11936 		    nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET]);
11937 
11938 	if (freq) {
11939 		connect.channel = nl80211_get_valid_chan(wiphy, freq);
11940 		if (!connect.channel)
11941 			return -EINVAL;
11942 	} else if (info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]) {
11943 		freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]);
11944 		freq = MHZ_TO_KHZ(freq);
11945 		connect.channel_hint = nl80211_get_valid_chan(wiphy, freq);
11946 		if (!connect.channel_hint)
11947 			return -EINVAL;
11948 	}
11949 
11950 	if (info->attrs[NL80211_ATTR_WIPHY_EDMG_CHANNELS]) {
11951 		connect.edmg.channels =
11952 		      nla_get_u8(info->attrs[NL80211_ATTR_WIPHY_EDMG_CHANNELS]);
11953 
11954 		if (info->attrs[NL80211_ATTR_WIPHY_EDMG_BW_CONFIG])
11955 			connect.edmg.bw_config =
11956 				nla_get_u8(info->attrs[NL80211_ATTR_WIPHY_EDMG_BW_CONFIG]);
11957 	}
11958 
11959 	if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
11960 		connkeys = nl80211_parse_connkeys(rdev, info, NULL);
11961 		if (IS_ERR(connkeys))
11962 			return PTR_ERR(connkeys);
11963 	}
11964 
11965 	if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
11966 		connect.flags |= ASSOC_REQ_DISABLE_HT;
11967 
11968 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
11969 		memcpy(&connect.ht_capa_mask,
11970 		       nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
11971 		       sizeof(connect.ht_capa_mask));
11972 
11973 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
11974 		if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
11975 			kfree_sensitive(connkeys);
11976 			return -EINVAL;
11977 		}
11978 		memcpy(&connect.ht_capa,
11979 		       nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
11980 		       sizeof(connect.ht_capa));
11981 	}
11982 
11983 	if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
11984 		connect.flags |= ASSOC_REQ_DISABLE_VHT;
11985 
11986 	if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HE]))
11987 		connect.flags |= ASSOC_REQ_DISABLE_HE;
11988 
11989 	if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_EHT]))
11990 		connect.flags |= ASSOC_REQ_DISABLE_EHT;
11991 
11992 	if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
11993 		memcpy(&connect.vht_capa_mask,
11994 		       nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
11995 		       sizeof(connect.vht_capa_mask));
11996 
11997 	if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
11998 		if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) {
11999 			kfree_sensitive(connkeys);
12000 			return -EINVAL;
12001 		}
12002 		memcpy(&connect.vht_capa,
12003 		       nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
12004 		       sizeof(connect.vht_capa));
12005 	}
12006 
12007 	if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) {
12008 		if (!((rdev->wiphy.features &
12009 			NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) &&
12010 		       (rdev->wiphy.features & NL80211_FEATURE_QUIET)) &&
12011 		    !wiphy_ext_feature_isset(&rdev->wiphy,
12012 					     NL80211_EXT_FEATURE_RRM)) {
12013 			kfree_sensitive(connkeys);
12014 			return -EINVAL;
12015 		}
12016 		connect.flags |= ASSOC_REQ_USE_RRM;
12017 	}
12018 
12019 	connect.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]);
12020 	if (connect.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ]) {
12021 		kfree_sensitive(connkeys);
12022 		return -EOPNOTSUPP;
12023 	}
12024 
12025 	if (info->attrs[NL80211_ATTR_BSS_SELECT]) {
12026 		/* bss selection makes no sense if bssid is set */
12027 		if (connect.bssid) {
12028 			kfree_sensitive(connkeys);
12029 			return -EINVAL;
12030 		}
12031 
12032 		err = parse_bss_select(info->attrs[NL80211_ATTR_BSS_SELECT],
12033 				       wiphy, &connect.bss_select);
12034 		if (err) {
12035 			kfree_sensitive(connkeys);
12036 			return err;
12037 		}
12038 	}
12039 
12040 	if (wiphy_ext_feature_isset(&rdev->wiphy,
12041 				    NL80211_EXT_FEATURE_FILS_SK_OFFLOAD) &&
12042 	    info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] &&
12043 	    info->attrs[NL80211_ATTR_FILS_ERP_REALM] &&
12044 	    info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] &&
12045 	    info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
12046 		connect.fils_erp_username =
12047 			nla_data(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
12048 		connect.fils_erp_username_len =
12049 			nla_len(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
12050 		connect.fils_erp_realm =
12051 			nla_data(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
12052 		connect.fils_erp_realm_len =
12053 			nla_len(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
12054 		connect.fils_erp_next_seq_num =
12055 			nla_get_u16(
12056 			   info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM]);
12057 		connect.fils_erp_rrk =
12058 			nla_data(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
12059 		connect.fils_erp_rrk_len =
12060 			nla_len(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
12061 	} else if (info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] ||
12062 		   info->attrs[NL80211_ATTR_FILS_ERP_REALM] ||
12063 		   info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] ||
12064 		   info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
12065 		kfree_sensitive(connkeys);
12066 		return -EINVAL;
12067 	}
12068 
12069 	if (nla_get_flag(info->attrs[NL80211_ATTR_EXTERNAL_AUTH_SUPPORT])) {
12070 		if (!info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
12071 			kfree_sensitive(connkeys);
12072 			GENL_SET_ERR_MSG(info,
12073 					 "external auth requires connection ownership");
12074 			return -EINVAL;
12075 		}
12076 		connect.flags |= CONNECT_REQ_EXTERNAL_AUTH_SUPPORT;
12077 	}
12078 
12079 	if (nla_get_flag(info->attrs[NL80211_ATTR_MLO_SUPPORT]))
12080 		connect.flags |= CONNECT_REQ_MLO_SUPPORT;
12081 
12082 	wdev_lock(dev->ieee80211_ptr);
12083 
12084 	err = cfg80211_connect(rdev, dev, &connect, connkeys,
12085 			       connect.prev_bssid);
12086 	if (err)
12087 		kfree_sensitive(connkeys);
12088 
12089 	if (!err && info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
12090 		dev->ieee80211_ptr->conn_owner_nlportid = info->snd_portid;
12091 		if (connect.bssid)
12092 			memcpy(dev->ieee80211_ptr->disconnect_bssid,
12093 			       connect.bssid, ETH_ALEN);
12094 		else
12095 			eth_zero_addr(dev->ieee80211_ptr->disconnect_bssid);
12096 	}
12097 
12098 	wdev_unlock(dev->ieee80211_ptr);
12099 
12100 	return err;
12101 }
12102 
nl80211_update_connect_params(struct sk_buff * skb,struct genl_info * info)12103 static int nl80211_update_connect_params(struct sk_buff *skb,
12104 					 struct genl_info *info)
12105 {
12106 	struct cfg80211_connect_params connect = {};
12107 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12108 	struct net_device *dev = info->user_ptr[1];
12109 	struct wireless_dev *wdev = dev->ieee80211_ptr;
12110 	bool fils_sk_offload;
12111 	u32 auth_type;
12112 	u32 changed = 0;
12113 	int ret;
12114 
12115 	if (!rdev->ops->update_connect_params)
12116 		return -EOPNOTSUPP;
12117 
12118 	if (info->attrs[NL80211_ATTR_IE]) {
12119 		connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
12120 		connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
12121 		changed |= UPDATE_ASSOC_IES;
12122 	}
12123 
12124 	fils_sk_offload = wiphy_ext_feature_isset(&rdev->wiphy,
12125 						  NL80211_EXT_FEATURE_FILS_SK_OFFLOAD);
12126 
12127 	/*
12128 	 * when driver supports fils-sk offload all attributes must be
12129 	 * provided. So the else covers "fils-sk-not-all" and
12130 	 * "no-fils-sk-any".
12131 	 */
12132 	if (fils_sk_offload &&
12133 	    info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] &&
12134 	    info->attrs[NL80211_ATTR_FILS_ERP_REALM] &&
12135 	    info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] &&
12136 	    info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
12137 		connect.fils_erp_username =
12138 			nla_data(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
12139 		connect.fils_erp_username_len =
12140 			nla_len(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
12141 		connect.fils_erp_realm =
12142 			nla_data(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
12143 		connect.fils_erp_realm_len =
12144 			nla_len(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
12145 		connect.fils_erp_next_seq_num =
12146 			nla_get_u16(
12147 			   info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM]);
12148 		connect.fils_erp_rrk =
12149 			nla_data(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
12150 		connect.fils_erp_rrk_len =
12151 			nla_len(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
12152 		changed |= UPDATE_FILS_ERP_INFO;
12153 	} else if (info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] ||
12154 		   info->attrs[NL80211_ATTR_FILS_ERP_REALM] ||
12155 		   info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] ||
12156 		   info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
12157 		return -EINVAL;
12158 	}
12159 
12160 	if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
12161 		auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
12162 		if (!nl80211_valid_auth_type(rdev, auth_type,
12163 					     NL80211_CMD_CONNECT))
12164 			return -EINVAL;
12165 
12166 		if (auth_type == NL80211_AUTHTYPE_FILS_SK &&
12167 		    fils_sk_offload && !(changed & UPDATE_FILS_ERP_INFO))
12168 			return -EINVAL;
12169 
12170 		connect.auth_type = auth_type;
12171 		changed |= UPDATE_AUTH_TYPE;
12172 	}
12173 
12174 	wdev_lock(dev->ieee80211_ptr);
12175 	if (!wdev->connected)
12176 		ret = -ENOLINK;
12177 	else
12178 		ret = rdev_update_connect_params(rdev, dev, &connect, changed);
12179 	wdev_unlock(dev->ieee80211_ptr);
12180 
12181 	return ret;
12182 }
12183 
nl80211_disconnect(struct sk_buff * skb,struct genl_info * info)12184 static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
12185 {
12186 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12187 	struct net_device *dev = info->user_ptr[1];
12188 	u16 reason;
12189 	int ret;
12190 
12191 	if (dev->ieee80211_ptr->conn_owner_nlportid &&
12192 	    dev->ieee80211_ptr->conn_owner_nlportid != info->snd_portid)
12193 		return -EPERM;
12194 
12195 	if (!info->attrs[NL80211_ATTR_REASON_CODE])
12196 		reason = WLAN_REASON_DEAUTH_LEAVING;
12197 	else
12198 		reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
12199 
12200 	if (reason == 0)
12201 		return -EINVAL;
12202 
12203 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
12204 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
12205 		return -EOPNOTSUPP;
12206 
12207 	wdev_lock(dev->ieee80211_ptr);
12208 	ret = cfg80211_disconnect(rdev, dev, reason, true);
12209 	wdev_unlock(dev->ieee80211_ptr);
12210 	return ret;
12211 }
12212 
nl80211_wiphy_netns(struct sk_buff * skb,struct genl_info * info)12213 static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
12214 {
12215 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12216 	struct net *net;
12217 	int err;
12218 
12219 	if (info->attrs[NL80211_ATTR_PID]) {
12220 		u32 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
12221 
12222 		net = get_net_ns_by_pid(pid);
12223 	} else if (info->attrs[NL80211_ATTR_NETNS_FD]) {
12224 		u32 fd = nla_get_u32(info->attrs[NL80211_ATTR_NETNS_FD]);
12225 
12226 		net = get_net_ns_by_fd(fd);
12227 	} else {
12228 		return -EINVAL;
12229 	}
12230 
12231 	if (IS_ERR(net))
12232 		return PTR_ERR(net);
12233 
12234 	err = 0;
12235 
12236 	/* check if anything to do */
12237 	if (!net_eq(wiphy_net(&rdev->wiphy), net))
12238 		err = cfg80211_switch_netns(rdev, net);
12239 
12240 	put_net(net);
12241 	return err;
12242 }
12243 
nl80211_setdel_pmksa(struct sk_buff * skb,struct genl_info * info)12244 static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
12245 {
12246 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12247 	int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
12248 			struct cfg80211_pmksa *pmksa) = NULL;
12249 	struct net_device *dev = info->user_ptr[1];
12250 	struct cfg80211_pmksa pmksa;
12251 
12252 	memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
12253 
12254 	if (!info->attrs[NL80211_ATTR_PMKID])
12255 		return -EINVAL;
12256 
12257 	pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
12258 
12259 	if (info->attrs[NL80211_ATTR_MAC]) {
12260 		pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
12261 	} else if (info->attrs[NL80211_ATTR_SSID] &&
12262 		   info->attrs[NL80211_ATTR_FILS_CACHE_ID] &&
12263 		   (info->genlhdr->cmd == NL80211_CMD_DEL_PMKSA ||
12264 		    info->attrs[NL80211_ATTR_PMK])) {
12265 		pmksa.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
12266 		pmksa.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
12267 		pmksa.cache_id =
12268 			nla_data(info->attrs[NL80211_ATTR_FILS_CACHE_ID]);
12269 	} else {
12270 		return -EINVAL;
12271 	}
12272 	if (info->attrs[NL80211_ATTR_PMK]) {
12273 		pmksa.pmk = nla_data(info->attrs[NL80211_ATTR_PMK]);
12274 		pmksa.pmk_len = nla_len(info->attrs[NL80211_ATTR_PMK]);
12275 	}
12276 
12277 	if (info->attrs[NL80211_ATTR_PMK_LIFETIME])
12278 		pmksa.pmk_lifetime =
12279 			nla_get_u32(info->attrs[NL80211_ATTR_PMK_LIFETIME]);
12280 
12281 	if (info->attrs[NL80211_ATTR_PMK_REAUTH_THRESHOLD])
12282 		pmksa.pmk_reauth_threshold =
12283 			nla_get_u8(
12284 				info->attrs[NL80211_ATTR_PMK_REAUTH_THRESHOLD]);
12285 
12286 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
12287 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
12288 	    !(dev->ieee80211_ptr->iftype == NL80211_IFTYPE_AP &&
12289 	      wiphy_ext_feature_isset(&rdev->wiphy,
12290 				      NL80211_EXT_FEATURE_AP_PMKSA_CACHING)))
12291 		return -EOPNOTSUPP;
12292 
12293 	switch (info->genlhdr->cmd) {
12294 	case NL80211_CMD_SET_PMKSA:
12295 		rdev_ops = rdev->ops->set_pmksa;
12296 		break;
12297 	case NL80211_CMD_DEL_PMKSA:
12298 		rdev_ops = rdev->ops->del_pmksa;
12299 		break;
12300 	default:
12301 		WARN_ON(1);
12302 		break;
12303 	}
12304 
12305 	if (!rdev_ops)
12306 		return -EOPNOTSUPP;
12307 
12308 	return rdev_ops(&rdev->wiphy, dev, &pmksa);
12309 }
12310 
nl80211_flush_pmksa(struct sk_buff * skb,struct genl_info * info)12311 static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
12312 {
12313 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12314 	struct net_device *dev = info->user_ptr[1];
12315 
12316 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
12317 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
12318 		return -EOPNOTSUPP;
12319 
12320 	if (!rdev->ops->flush_pmksa)
12321 		return -EOPNOTSUPP;
12322 
12323 	return rdev_flush_pmksa(rdev, dev);
12324 }
12325 
nl80211_tdls_mgmt(struct sk_buff * skb,struct genl_info * info)12326 static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
12327 {
12328 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12329 	struct net_device *dev = info->user_ptr[1];
12330 	u8 action_code, dialog_token;
12331 	u32 peer_capability = 0;
12332 	u16 status_code;
12333 	u8 *peer;
12334 	int link_id;
12335 	bool initiator;
12336 
12337 	if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
12338 	    !rdev->ops->tdls_mgmt)
12339 		return -EOPNOTSUPP;
12340 
12341 	if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
12342 	    !info->attrs[NL80211_ATTR_STATUS_CODE] ||
12343 	    !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
12344 	    !info->attrs[NL80211_ATTR_IE] ||
12345 	    !info->attrs[NL80211_ATTR_MAC])
12346 		return -EINVAL;
12347 
12348 	peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
12349 	action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
12350 	status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
12351 	dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
12352 	initiator = nla_get_flag(info->attrs[NL80211_ATTR_TDLS_INITIATOR]);
12353 	if (info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY])
12354 		peer_capability =
12355 			nla_get_u32(info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY]);
12356 	link_id = nl80211_link_id_or_invalid(info->attrs);
12357 
12358 	return rdev_tdls_mgmt(rdev, dev, peer, link_id, action_code,
12359 			      dialog_token, status_code, peer_capability,
12360 			      initiator,
12361 			      nla_data(info->attrs[NL80211_ATTR_IE]),
12362 			      nla_len(info->attrs[NL80211_ATTR_IE]));
12363 }
12364 
nl80211_tdls_oper(struct sk_buff * skb,struct genl_info * info)12365 static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
12366 {
12367 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12368 	struct net_device *dev = info->user_ptr[1];
12369 	enum nl80211_tdls_operation operation;
12370 	u8 *peer;
12371 
12372 	if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
12373 	    !rdev->ops->tdls_oper)
12374 		return -EOPNOTSUPP;
12375 
12376 	if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
12377 	    !info->attrs[NL80211_ATTR_MAC])
12378 		return -EINVAL;
12379 
12380 	operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
12381 	peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
12382 
12383 	return rdev_tdls_oper(rdev, dev, peer, operation);
12384 }
12385 
nl80211_remain_on_channel(struct sk_buff * skb,struct genl_info * info)12386 static int nl80211_remain_on_channel(struct sk_buff *skb,
12387 				     struct genl_info *info)
12388 {
12389 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12390 	unsigned int link_id = nl80211_link_id(info->attrs);
12391 	struct wireless_dev *wdev = info->user_ptr[1];
12392 	struct cfg80211_chan_def chandef;
12393 	struct sk_buff *msg;
12394 	void *hdr;
12395 	u64 cookie;
12396 	u32 duration;
12397 	int err;
12398 
12399 	if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
12400 	    !info->attrs[NL80211_ATTR_DURATION])
12401 		return -EINVAL;
12402 
12403 	duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
12404 
12405 	if (!rdev->ops->remain_on_channel ||
12406 	    !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
12407 		return -EOPNOTSUPP;
12408 
12409 	/*
12410 	 * We should be on that channel for at least a minimum amount of
12411 	 * time (10ms) but no longer than the driver supports.
12412 	 */
12413 	if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
12414 	    duration > rdev->wiphy.max_remain_on_channel_duration)
12415 		return -EINVAL;
12416 
12417 	err = nl80211_parse_chandef(rdev, info, &chandef);
12418 	if (err)
12419 		return err;
12420 
12421 	wdev_lock(wdev);
12422 	if (!cfg80211_off_channel_oper_allowed(wdev, chandef.chan)) {
12423 		const struct cfg80211_chan_def *oper_chandef, *compat_chandef;
12424 
12425 		oper_chandef = wdev_chandef(wdev, link_id);
12426 
12427 		if (WARN_ON(!oper_chandef)) {
12428 			/* cannot happen since we must beacon to get here */
12429 			WARN_ON(1);
12430 			wdev_unlock(wdev);
12431 			return -EBUSY;
12432 		}
12433 
12434 		/* note: returns first one if identical chandefs */
12435 		compat_chandef = cfg80211_chandef_compatible(&chandef,
12436 							     oper_chandef);
12437 
12438 		if (compat_chandef != &chandef) {
12439 			wdev_unlock(wdev);
12440 			return -EBUSY;
12441 		}
12442 	}
12443 	wdev_unlock(wdev);
12444 
12445 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
12446 	if (!msg)
12447 		return -ENOMEM;
12448 
12449 	hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
12450 			     NL80211_CMD_REMAIN_ON_CHANNEL);
12451 	if (!hdr) {
12452 		err = -ENOBUFS;
12453 		goto free_msg;
12454 	}
12455 
12456 	err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
12457 				     duration, &cookie);
12458 
12459 	if (err)
12460 		goto free_msg;
12461 
12462 	if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
12463 			      NL80211_ATTR_PAD))
12464 		goto nla_put_failure;
12465 
12466 	genlmsg_end(msg, hdr);
12467 
12468 	return genlmsg_reply(msg, info);
12469 
12470  nla_put_failure:
12471 	err = -ENOBUFS;
12472  free_msg:
12473 	nlmsg_free(msg);
12474 	return err;
12475 }
12476 
nl80211_cancel_remain_on_channel(struct sk_buff * skb,struct genl_info * info)12477 static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
12478 					    struct genl_info *info)
12479 {
12480 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12481 	struct wireless_dev *wdev = info->user_ptr[1];
12482 	u64 cookie;
12483 
12484 	if (!info->attrs[NL80211_ATTR_COOKIE])
12485 		return -EINVAL;
12486 
12487 	if (!rdev->ops->cancel_remain_on_channel)
12488 		return -EOPNOTSUPP;
12489 
12490 	cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
12491 
12492 	return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
12493 }
12494 
nl80211_set_tx_bitrate_mask(struct sk_buff * skb,struct genl_info * info)12495 static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
12496 				       struct genl_info *info)
12497 {
12498 	struct cfg80211_bitrate_mask mask;
12499 	unsigned int link_id = nl80211_link_id(info->attrs);
12500 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12501 	struct net_device *dev = info->user_ptr[1];
12502 	struct wireless_dev *wdev = dev->ieee80211_ptr;
12503 	int err;
12504 
12505 	if (!rdev->ops->set_bitrate_mask)
12506 		return -EOPNOTSUPP;
12507 
12508 	wdev_lock(wdev);
12509 	err = nl80211_parse_tx_bitrate_mask(info, info->attrs,
12510 					    NL80211_ATTR_TX_RATES, &mask,
12511 					    dev, true, link_id);
12512 	if (err)
12513 		goto out;
12514 
12515 	err = rdev_set_bitrate_mask(rdev, dev, link_id, NULL, &mask);
12516 out:
12517 	wdev_unlock(wdev);
12518 	return err;
12519 }
12520 
nl80211_register_mgmt(struct sk_buff * skb,struct genl_info * info)12521 static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
12522 {
12523 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12524 	struct wireless_dev *wdev = info->user_ptr[1];
12525 	u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
12526 
12527 	if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
12528 		return -EINVAL;
12529 
12530 	if (info->attrs[NL80211_ATTR_FRAME_TYPE])
12531 		frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
12532 
12533 	switch (wdev->iftype) {
12534 	case NL80211_IFTYPE_STATION:
12535 	case NL80211_IFTYPE_ADHOC:
12536 	case NL80211_IFTYPE_P2P_CLIENT:
12537 	case NL80211_IFTYPE_AP:
12538 	case NL80211_IFTYPE_AP_VLAN:
12539 	case NL80211_IFTYPE_MESH_POINT:
12540 	case NL80211_IFTYPE_P2P_GO:
12541 	case NL80211_IFTYPE_P2P_DEVICE:
12542 		break;
12543 	case NL80211_IFTYPE_NAN:
12544 		if (!wiphy_ext_feature_isset(wdev->wiphy,
12545 					     NL80211_EXT_FEATURE_SECURE_NAN))
12546 			return -EOPNOTSUPP;
12547 		break;
12548 	default:
12549 		return -EOPNOTSUPP;
12550 	}
12551 
12552 	/* not much point in registering if we can't reply */
12553 	if (!rdev->ops->mgmt_tx)
12554 		return -EOPNOTSUPP;
12555 
12556 	if (info->attrs[NL80211_ATTR_RECEIVE_MULTICAST] &&
12557 	    !wiphy_ext_feature_isset(&rdev->wiphy,
12558 				     NL80211_EXT_FEATURE_MULTICAST_REGISTRATIONS)) {
12559 		GENL_SET_ERR_MSG(info,
12560 				 "multicast RX registrations are not supported");
12561 		return -EOPNOTSUPP;
12562 	}
12563 
12564 	return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
12565 					   nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
12566 					   nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]),
12567 					   info->attrs[NL80211_ATTR_RECEIVE_MULTICAST],
12568 					   info->extack);
12569 }
12570 
nl80211_tx_mgmt(struct sk_buff * skb,struct genl_info * info)12571 static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
12572 {
12573 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12574 	struct wireless_dev *wdev = info->user_ptr[1];
12575 	struct cfg80211_chan_def chandef;
12576 	int err;
12577 	void *hdr = NULL;
12578 	u64 cookie;
12579 	struct sk_buff *msg = NULL;
12580 	struct cfg80211_mgmt_tx_params params = {
12581 		.dont_wait_for_ack =
12582 			info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK],
12583 	};
12584 
12585 	if (!info->attrs[NL80211_ATTR_FRAME])
12586 		return -EINVAL;
12587 
12588 	if (!rdev->ops->mgmt_tx)
12589 		return -EOPNOTSUPP;
12590 
12591 	switch (wdev->iftype) {
12592 	case NL80211_IFTYPE_P2P_DEVICE:
12593 		if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
12594 			return -EINVAL;
12595 		break;
12596 	case NL80211_IFTYPE_STATION:
12597 	case NL80211_IFTYPE_ADHOC:
12598 	case NL80211_IFTYPE_P2P_CLIENT:
12599 	case NL80211_IFTYPE_AP:
12600 	case NL80211_IFTYPE_AP_VLAN:
12601 	case NL80211_IFTYPE_MESH_POINT:
12602 	case NL80211_IFTYPE_P2P_GO:
12603 		break;
12604 	case NL80211_IFTYPE_NAN:
12605 		if (!wiphy_ext_feature_isset(wdev->wiphy,
12606 					     NL80211_EXT_FEATURE_SECURE_NAN))
12607 			return -EOPNOTSUPP;
12608 		break;
12609 	default:
12610 		return -EOPNOTSUPP;
12611 	}
12612 
12613 	if (info->attrs[NL80211_ATTR_DURATION]) {
12614 		if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
12615 			return -EINVAL;
12616 		params.wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
12617 
12618 		/*
12619 		 * We should wait on the channel for at least a minimum amount
12620 		 * of time (10ms) but no longer than the driver supports.
12621 		 */
12622 		if (params.wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
12623 		    params.wait > rdev->wiphy.max_remain_on_channel_duration)
12624 			return -EINVAL;
12625 	}
12626 
12627 	params.offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
12628 
12629 	if (params.offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
12630 		return -EINVAL;
12631 
12632 	params.no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
12633 
12634 	/* get the channel if any has been specified, otherwise pass NULL to
12635 	 * the driver. The latter will use the current one
12636 	 */
12637 	chandef.chan = NULL;
12638 	if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
12639 		err = nl80211_parse_chandef(rdev, info, &chandef);
12640 		if (err)
12641 			return err;
12642 	}
12643 
12644 	if (!chandef.chan && params.offchan)
12645 		return -EINVAL;
12646 
12647 	wdev_lock(wdev);
12648 	if (params.offchan &&
12649 	    !cfg80211_off_channel_oper_allowed(wdev, chandef.chan)) {
12650 		wdev_unlock(wdev);
12651 		return -EBUSY;
12652 	}
12653 
12654 	params.link_id = nl80211_link_id_or_invalid(info->attrs);
12655 	/*
12656 	 * This now races due to the unlock, but we cannot check
12657 	 * the valid links for the _station_ anyway, so that's up
12658 	 * to the driver.
12659 	 */
12660 	if (params.link_id >= 0 &&
12661 	    !(wdev->valid_links & BIT(params.link_id))) {
12662 		wdev_unlock(wdev);
12663 		return -EINVAL;
12664 	}
12665 	wdev_unlock(wdev);
12666 
12667 	params.buf = nla_data(info->attrs[NL80211_ATTR_FRAME]);
12668 	params.len = nla_len(info->attrs[NL80211_ATTR_FRAME]);
12669 
12670 	if (info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]) {
12671 		int len = nla_len(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]);
12672 		int i;
12673 
12674 		if (len % sizeof(u16))
12675 			return -EINVAL;
12676 
12677 		params.n_csa_offsets = len / sizeof(u16);
12678 		params.csa_offsets =
12679 			nla_data(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]);
12680 
12681 		/* check that all the offsets fit the frame */
12682 		for (i = 0; i < params.n_csa_offsets; i++) {
12683 			if (params.csa_offsets[i] >= params.len)
12684 				return -EINVAL;
12685 		}
12686 	}
12687 
12688 	if (!params.dont_wait_for_ack) {
12689 		msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
12690 		if (!msg)
12691 			return -ENOMEM;
12692 
12693 		hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
12694 				     NL80211_CMD_FRAME);
12695 		if (!hdr) {
12696 			err = -ENOBUFS;
12697 			goto free_msg;
12698 		}
12699 	}
12700 
12701 	params.chan = chandef.chan;
12702 	err = cfg80211_mlme_mgmt_tx(rdev, wdev, &params, &cookie);
12703 	if (err)
12704 		goto free_msg;
12705 
12706 	if (msg) {
12707 		if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
12708 				      NL80211_ATTR_PAD))
12709 			goto nla_put_failure;
12710 
12711 		genlmsg_end(msg, hdr);
12712 		return genlmsg_reply(msg, info);
12713 	}
12714 
12715 	return 0;
12716 
12717  nla_put_failure:
12718 	err = -ENOBUFS;
12719  free_msg:
12720 	nlmsg_free(msg);
12721 	return err;
12722 }
12723 
nl80211_tx_mgmt_cancel_wait(struct sk_buff * skb,struct genl_info * info)12724 static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
12725 {
12726 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12727 	struct wireless_dev *wdev = info->user_ptr[1];
12728 	u64 cookie;
12729 
12730 	if (!info->attrs[NL80211_ATTR_COOKIE])
12731 		return -EINVAL;
12732 
12733 	if (!rdev->ops->mgmt_tx_cancel_wait)
12734 		return -EOPNOTSUPP;
12735 
12736 	switch (wdev->iftype) {
12737 	case NL80211_IFTYPE_STATION:
12738 	case NL80211_IFTYPE_ADHOC:
12739 	case NL80211_IFTYPE_P2P_CLIENT:
12740 	case NL80211_IFTYPE_AP:
12741 	case NL80211_IFTYPE_AP_VLAN:
12742 	case NL80211_IFTYPE_P2P_GO:
12743 	case NL80211_IFTYPE_P2P_DEVICE:
12744 		break;
12745 	case NL80211_IFTYPE_NAN:
12746 		if (!wiphy_ext_feature_isset(wdev->wiphy,
12747 					     NL80211_EXT_FEATURE_SECURE_NAN))
12748 			return -EOPNOTSUPP;
12749 		break;
12750 	default:
12751 		return -EOPNOTSUPP;
12752 	}
12753 
12754 	cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
12755 
12756 	return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
12757 }
12758 
nl80211_set_power_save(struct sk_buff * skb,struct genl_info * info)12759 static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
12760 {
12761 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12762 	struct wireless_dev *wdev;
12763 	struct net_device *dev = info->user_ptr[1];
12764 	u8 ps_state;
12765 	bool state;
12766 	int err;
12767 
12768 	if (!info->attrs[NL80211_ATTR_PS_STATE])
12769 		return -EINVAL;
12770 
12771 	ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
12772 
12773 	wdev = dev->ieee80211_ptr;
12774 
12775 	if (!rdev->ops->set_power_mgmt)
12776 		return -EOPNOTSUPP;
12777 
12778 	state = (ps_state == NL80211_PS_ENABLED) ? true : false;
12779 
12780 	if (state == wdev->ps)
12781 		return 0;
12782 
12783 	err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
12784 	if (!err)
12785 		wdev->ps = state;
12786 	return err;
12787 }
12788 
nl80211_get_power_save(struct sk_buff * skb,struct genl_info * info)12789 static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
12790 {
12791 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12792 	enum nl80211_ps_state ps_state;
12793 	struct wireless_dev *wdev;
12794 	struct net_device *dev = info->user_ptr[1];
12795 	struct sk_buff *msg;
12796 	void *hdr;
12797 	int err;
12798 
12799 	wdev = dev->ieee80211_ptr;
12800 
12801 	if (!rdev->ops->set_power_mgmt)
12802 		return -EOPNOTSUPP;
12803 
12804 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
12805 	if (!msg)
12806 		return -ENOMEM;
12807 
12808 	hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
12809 			     NL80211_CMD_GET_POWER_SAVE);
12810 	if (!hdr) {
12811 		err = -ENOBUFS;
12812 		goto free_msg;
12813 	}
12814 
12815 	if (wdev->ps)
12816 		ps_state = NL80211_PS_ENABLED;
12817 	else
12818 		ps_state = NL80211_PS_DISABLED;
12819 
12820 	if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
12821 		goto nla_put_failure;
12822 
12823 	genlmsg_end(msg, hdr);
12824 	return genlmsg_reply(msg, info);
12825 
12826  nla_put_failure:
12827 	err = -ENOBUFS;
12828  free_msg:
12829 	nlmsg_free(msg);
12830 	return err;
12831 }
12832 
12833 static const struct nla_policy
12834 nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] = {
12835 	[NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_BINARY },
12836 	[NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
12837 	[NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
12838 	[NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
12839 	[NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
12840 	[NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
12841 	[NL80211_ATTR_CQM_RSSI_LEVEL] = { .type = NLA_S32 },
12842 };
12843 
nl80211_set_cqm_txe(struct genl_info * info,u32 rate,u32 pkts,u32 intvl)12844 static int nl80211_set_cqm_txe(struct genl_info *info,
12845 			       u32 rate, u32 pkts, u32 intvl)
12846 {
12847 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12848 	struct net_device *dev = info->user_ptr[1];
12849 	struct wireless_dev *wdev = dev->ieee80211_ptr;
12850 
12851 	if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
12852 		return -EINVAL;
12853 
12854 	if (!rdev->ops->set_cqm_txe_config)
12855 		return -EOPNOTSUPP;
12856 
12857 	if (wdev->iftype != NL80211_IFTYPE_STATION &&
12858 	    wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
12859 		return -EOPNOTSUPP;
12860 
12861 	return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
12862 }
12863 
cfg80211_cqm_rssi_update(struct cfg80211_registered_device * rdev,struct net_device * dev,struct cfg80211_cqm_config * cqm_config)12864 static int cfg80211_cqm_rssi_update(struct cfg80211_registered_device *rdev,
12865 				    struct net_device *dev,
12866 				    struct cfg80211_cqm_config *cqm_config)
12867 {
12868 	struct wireless_dev *wdev = dev->ieee80211_ptr;
12869 	s32 last, low, high;
12870 	u32 hyst;
12871 	int i, n, low_index;
12872 	int err;
12873 
12874 	/*
12875 	 * Obtain current RSSI value if possible, if not and no RSSI threshold
12876 	 * event has been received yet, we should receive an event after a
12877 	 * connection is established and enough beacons received to calculate
12878 	 * the average.
12879 	 */
12880 	if (!cqm_config->last_rssi_event_value &&
12881 	    wdev->links[0].client.current_bss &&
12882 	    rdev->ops->get_station) {
12883 		struct station_info sinfo = {};
12884 		u8 *mac_addr;
12885 
12886 		mac_addr = wdev->links[0].client.current_bss->pub.bssid;
12887 
12888 		err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
12889 		if (err)
12890 			return err;
12891 
12892 		cfg80211_sinfo_release_content(&sinfo);
12893 		if (sinfo.filled & BIT_ULL(NL80211_STA_INFO_BEACON_SIGNAL_AVG))
12894 			cqm_config->last_rssi_event_value =
12895 				(s8) sinfo.rx_beacon_signal_avg;
12896 	}
12897 
12898 	last = cqm_config->last_rssi_event_value;
12899 	hyst = cqm_config->rssi_hyst;
12900 	n = cqm_config->n_rssi_thresholds;
12901 
12902 	for (i = 0; i < n; i++) {
12903 		i = array_index_nospec(i, n);
12904 		if (last < cqm_config->rssi_thresholds[i])
12905 			break;
12906 	}
12907 
12908 	low_index = i - 1;
12909 	if (low_index >= 0) {
12910 		low_index = array_index_nospec(low_index, n);
12911 		low = cqm_config->rssi_thresholds[low_index] - hyst;
12912 	} else {
12913 		low = S32_MIN;
12914 	}
12915 	if (i < n) {
12916 		i = array_index_nospec(i, n);
12917 		high = cqm_config->rssi_thresholds[i] + hyst - 1;
12918 	} else {
12919 		high = S32_MAX;
12920 	}
12921 
12922 	return rdev_set_cqm_rssi_range_config(rdev, dev, low, high);
12923 }
12924 
nl80211_set_cqm_rssi(struct genl_info * info,const s32 * thresholds,int n_thresholds,u32 hysteresis)12925 static int nl80211_set_cqm_rssi(struct genl_info *info,
12926 				const s32 *thresholds, int n_thresholds,
12927 				u32 hysteresis)
12928 {
12929 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
12930 	struct cfg80211_cqm_config *cqm_config = NULL, *old;
12931 	struct net_device *dev = info->user_ptr[1];
12932 	struct wireless_dev *wdev = dev->ieee80211_ptr;
12933 	int i, err;
12934 	s32 prev = S32_MIN;
12935 
12936 	/* Check all values negative and sorted */
12937 	for (i = 0; i < n_thresholds; i++) {
12938 		if (thresholds[i] > 0 || thresholds[i] <= prev)
12939 			return -EINVAL;
12940 
12941 		prev = thresholds[i];
12942 	}
12943 
12944 	if (wdev->iftype != NL80211_IFTYPE_STATION &&
12945 	    wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
12946 		return -EOPNOTSUPP;
12947 
12948 	if (n_thresholds == 1 && thresholds[0] == 0) /* Disabling */
12949 		n_thresholds = 0;
12950 
12951 	wdev_lock(wdev);
12952 	old = rcu_dereference_protected(wdev->cqm_config,
12953 					lockdep_is_held(&wdev->mtx));
12954 
12955 	/* if already disabled just succeed */
12956 	if (!n_thresholds && !old) {
12957 		err = 0;
12958 		goto unlock;
12959 	}
12960 
12961 	if (n_thresholds > 1) {
12962 		if (!wiphy_ext_feature_isset(&rdev->wiphy,
12963 					     NL80211_EXT_FEATURE_CQM_RSSI_LIST) ||
12964 		    !rdev->ops->set_cqm_rssi_range_config) {
12965 			err = -EOPNOTSUPP;
12966 			goto unlock;
12967 		}
12968 	} else {
12969 		if (!rdev->ops->set_cqm_rssi_config) {
12970 			err = -EOPNOTSUPP;
12971 			goto unlock;
12972 		}
12973 	}
12974 
12975 	if (n_thresholds) {
12976 		cqm_config = kzalloc(struct_size(cqm_config, rssi_thresholds,
12977 						 n_thresholds),
12978 				     GFP_KERNEL);
12979 		if (!cqm_config) {
12980 			err = -ENOMEM;
12981 			goto unlock;
12982 		}
12983 
12984 		cqm_config->rssi_hyst = hysteresis;
12985 		cqm_config->n_rssi_thresholds = n_thresholds;
12986 		memcpy(cqm_config->rssi_thresholds, thresholds,
12987 		       flex_array_size(cqm_config, rssi_thresholds,
12988 				       n_thresholds));
12989 		cqm_config->use_range_api = n_thresholds > 1 ||
12990 					    !rdev->ops->set_cqm_rssi_config;
12991 
12992 		rcu_assign_pointer(wdev->cqm_config, cqm_config);
12993 
12994 		if (cqm_config->use_range_api)
12995 			err = cfg80211_cqm_rssi_update(rdev, dev, cqm_config);
12996 		else
12997 			err = rdev_set_cqm_rssi_config(rdev, dev,
12998 						       thresholds[0],
12999 						       hysteresis);
13000 	} else {
13001 		RCU_INIT_POINTER(wdev->cqm_config, NULL);
13002 		/* if enabled as range also disable via range */
13003 		if (old->use_range_api)
13004 			err = rdev_set_cqm_rssi_range_config(rdev, dev, 0, 0);
13005 		else
13006 			err = rdev_set_cqm_rssi_config(rdev, dev, 0, 0);
13007 	}
13008 
13009 	if (err) {
13010 		rcu_assign_pointer(wdev->cqm_config, old);
13011 		kfree_rcu(cqm_config, rcu_head);
13012 	} else {
13013 		kfree_rcu(old, rcu_head);
13014 	}
13015 unlock:
13016 	wdev_unlock(wdev);
13017 
13018 	return err;
13019 }
13020 
nl80211_set_cqm(struct sk_buff * skb,struct genl_info * info)13021 static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
13022 {
13023 	struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
13024 	struct nlattr *cqm;
13025 	int err;
13026 
13027 	cqm = info->attrs[NL80211_ATTR_CQM];
13028 	if (!cqm)
13029 		return -EINVAL;
13030 
13031 	err = nla_parse_nested_deprecated(attrs, NL80211_ATTR_CQM_MAX, cqm,
13032 					  nl80211_attr_cqm_policy,
13033 					  info->extack);
13034 	if (err)
13035 		return err;
13036 
13037 	if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
13038 	    attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
13039 		const s32 *thresholds =
13040 			nla_data(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
13041 		int len = nla_len(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
13042 		u32 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
13043 
13044 		if (len % 4)
13045 			return -EINVAL;
13046 
13047 		return nl80211_set_cqm_rssi(info, thresholds, len / 4,
13048 					    hysteresis);
13049 	}
13050 
13051 	if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
13052 	    attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
13053 	    attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
13054 		u32 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
13055 		u32 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
13056 		u32 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
13057 
13058 		return nl80211_set_cqm_txe(info, rate, pkts, intvl);
13059 	}
13060 
13061 	return -EINVAL;
13062 }
13063 
nl80211_join_ocb(struct sk_buff * skb,struct genl_info * info)13064 static int nl80211_join_ocb(struct sk_buff *skb, struct genl_info *info)
13065 {
13066 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
13067 	struct net_device *dev = info->user_ptr[1];
13068 	struct ocb_setup setup = {};
13069 	int err;
13070 
13071 	err = nl80211_parse_chandef(rdev, info, &setup.chandef);
13072 	if (err)
13073 		return err;
13074 
13075 	return cfg80211_join_ocb(rdev, dev, &setup);
13076 }
13077 
nl80211_leave_ocb(struct sk_buff * skb,struct genl_info * info)13078 static int nl80211_leave_ocb(struct sk_buff *skb, struct genl_info *info)
13079 {
13080 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
13081 	struct net_device *dev = info->user_ptr[1];
13082 
13083 	return cfg80211_leave_ocb(rdev, dev);
13084 }
13085 
nl80211_join_mesh(struct sk_buff * skb,struct genl_info * info)13086 static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
13087 {
13088 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
13089 	struct net_device *dev = info->user_ptr[1];
13090 	struct mesh_config cfg;
13091 	struct mesh_setup setup;
13092 	int err;
13093 
13094 	/* start with default */
13095 	memcpy(&cfg, &default_mesh_config, sizeof(cfg));
13096 	memcpy(&setup, &default_mesh_setup, sizeof(setup));
13097 
13098 	if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
13099 		/* and parse parameters if given */
13100 		err = nl80211_parse_mesh_config(info, &cfg, NULL);
13101 		if (err)
13102 			return err;
13103 	}
13104 
13105 	if (!info->attrs[NL80211_ATTR_MESH_ID] ||
13106 	    !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
13107 		return -EINVAL;
13108 
13109 	setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
13110 	setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
13111 
13112 	if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
13113 	    !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
13114 			    nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
13115 			return -EINVAL;
13116 
13117 	if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
13118 		setup.beacon_interval =
13119 			nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
13120 
13121 		err = cfg80211_validate_beacon_int(rdev,
13122 						   NL80211_IFTYPE_MESH_POINT,
13123 						   setup.beacon_interval);
13124 		if (err)
13125 			return err;
13126 	}
13127 
13128 	if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
13129 		setup.dtim_period =
13130 			nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
13131 		if (setup.dtim_period < 1 || setup.dtim_period > 100)
13132 			return -EINVAL;
13133 	}
13134 
13135 	if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
13136 		/* parse additional setup parameters if given */
13137 		err = nl80211_parse_mesh_setup(info, &setup);
13138 		if (err)
13139 			return err;
13140 	}
13141 
13142 	if (setup.user_mpm)
13143 		cfg.auto_open_plinks = false;
13144 
13145 	if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
13146 		err = nl80211_parse_chandef(rdev, info, &setup.chandef);
13147 		if (err)
13148 			return err;
13149 	} else {
13150 		/* __cfg80211_join_mesh() will sort it out */
13151 		setup.chandef.chan = NULL;
13152 	}
13153 
13154 	if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
13155 		u8 *rates = nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
13156 		int n_rates =
13157 			nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
13158 		struct ieee80211_supported_band *sband;
13159 
13160 		if (!setup.chandef.chan)
13161 			return -EINVAL;
13162 
13163 		sband = rdev->wiphy.bands[setup.chandef.chan->band];
13164 
13165 		err = ieee80211_get_ratemask(sband, rates, n_rates,
13166 					     &setup.basic_rates);
13167 		if (err)
13168 			return err;
13169 	}
13170 
13171 	if (info->attrs[NL80211_ATTR_TX_RATES]) {
13172 		err = nl80211_parse_tx_bitrate_mask(info, info->attrs,
13173 						    NL80211_ATTR_TX_RATES,
13174 						    &setup.beacon_rate,
13175 						    dev, false, 0);
13176 		if (err)
13177 			return err;
13178 
13179 		if (!setup.chandef.chan)
13180 			return -EINVAL;
13181 
13182 		err = validate_beacon_tx_rate(rdev, setup.chandef.chan->band,
13183 					      &setup.beacon_rate);
13184 		if (err)
13185 			return err;
13186 	}
13187 
13188 	setup.userspace_handles_dfs =
13189 		nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]);
13190 
13191 	if (info->attrs[NL80211_ATTR_CONTROL_PORT_OVER_NL80211]) {
13192 		int r = validate_pae_over_nl80211(rdev, info);
13193 
13194 		if (r < 0)
13195 			return r;
13196 
13197 		setup.control_port_over_nl80211 = true;
13198 	}
13199 
13200 	wdev_lock(dev->ieee80211_ptr);
13201 	err = __cfg80211_join_mesh(rdev, dev, &setup, &cfg);
13202 	if (!err && info->attrs[NL80211_ATTR_SOCKET_OWNER])
13203 		dev->ieee80211_ptr->conn_owner_nlportid = info->snd_portid;
13204 	wdev_unlock(dev->ieee80211_ptr);
13205 
13206 	return err;
13207 }
13208 
nl80211_leave_mesh(struct sk_buff * skb,struct genl_info * info)13209 static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
13210 {
13211 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
13212 	struct net_device *dev = info->user_ptr[1];
13213 
13214 	return cfg80211_leave_mesh(rdev, dev);
13215 }
13216 
13217 #ifdef CONFIG_PM
nl80211_send_wowlan_patterns(struct sk_buff * msg,struct cfg80211_registered_device * rdev)13218 static int nl80211_send_wowlan_patterns(struct sk_buff *msg,
13219 					struct cfg80211_registered_device *rdev)
13220 {
13221 	struct cfg80211_wowlan *wowlan = rdev->wiphy.wowlan_config;
13222 	struct nlattr *nl_pats, *nl_pat;
13223 	int i, pat_len;
13224 
13225 	if (!wowlan->n_patterns)
13226 		return 0;
13227 
13228 	nl_pats = nla_nest_start_noflag(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN);
13229 	if (!nl_pats)
13230 		return -ENOBUFS;
13231 
13232 	for (i = 0; i < wowlan->n_patterns; i++) {
13233 		nl_pat = nla_nest_start_noflag(msg, i + 1);
13234 		if (!nl_pat)
13235 			return -ENOBUFS;
13236 		pat_len = wowlan->patterns[i].pattern_len;
13237 		if (nla_put(msg, NL80211_PKTPAT_MASK, DIV_ROUND_UP(pat_len, 8),
13238 			    wowlan->patterns[i].mask) ||
13239 		    nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
13240 			    wowlan->patterns[i].pattern) ||
13241 		    nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
13242 				wowlan->patterns[i].pkt_offset))
13243 			return -ENOBUFS;
13244 		nla_nest_end(msg, nl_pat);
13245 	}
13246 	nla_nest_end(msg, nl_pats);
13247 
13248 	return 0;
13249 }
13250 
nl80211_send_wowlan_tcp(struct sk_buff * msg,struct cfg80211_wowlan_tcp * tcp)13251 static int nl80211_send_wowlan_tcp(struct sk_buff *msg,
13252 				   struct cfg80211_wowlan_tcp *tcp)
13253 {
13254 	struct nlattr *nl_tcp;
13255 
13256 	if (!tcp)
13257 		return 0;
13258 
13259 	nl_tcp = nla_nest_start_noflag(msg,
13260 				       NL80211_WOWLAN_TRIG_TCP_CONNECTION);
13261 	if (!nl_tcp)
13262 		return -ENOBUFS;
13263 
13264 	if (nla_put_in_addr(msg, NL80211_WOWLAN_TCP_SRC_IPV4, tcp->src) ||
13265 	    nla_put_in_addr(msg, NL80211_WOWLAN_TCP_DST_IPV4, tcp->dst) ||
13266 	    nla_put(msg, NL80211_WOWLAN_TCP_DST_MAC, ETH_ALEN, tcp->dst_mac) ||
13267 	    nla_put_u16(msg, NL80211_WOWLAN_TCP_SRC_PORT, tcp->src_port) ||
13268 	    nla_put_u16(msg, NL80211_WOWLAN_TCP_DST_PORT, tcp->dst_port) ||
13269 	    nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
13270 		    tcp->payload_len, tcp->payload) ||
13271 	    nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
13272 			tcp->data_interval) ||
13273 	    nla_put(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
13274 		    tcp->wake_len, tcp->wake_data) ||
13275 	    nla_put(msg, NL80211_WOWLAN_TCP_WAKE_MASK,
13276 		    DIV_ROUND_UP(tcp->wake_len, 8), tcp->wake_mask))
13277 		return -ENOBUFS;
13278 
13279 	if (tcp->payload_seq.len &&
13280 	    nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ,
13281 		    sizeof(tcp->payload_seq), &tcp->payload_seq))
13282 		return -ENOBUFS;
13283 
13284 	if (tcp->payload_tok.len &&
13285 	    nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
13286 		    sizeof(tcp->payload_tok) + tcp->tokens_size,
13287 		    &tcp->payload_tok))
13288 		return -ENOBUFS;
13289 
13290 	nla_nest_end(msg, nl_tcp);
13291 
13292 	return 0;
13293 }
13294 
nl80211_send_wowlan_nd(struct sk_buff * msg,struct cfg80211_sched_scan_request * req)13295 static int nl80211_send_wowlan_nd(struct sk_buff *msg,
13296 				  struct cfg80211_sched_scan_request *req)
13297 {
13298 	struct nlattr *nd, *freqs, *matches, *match, *scan_plans, *scan_plan;
13299 	int i;
13300 
13301 	if (!req)
13302 		return 0;
13303 
13304 	nd = nla_nest_start_noflag(msg, NL80211_WOWLAN_TRIG_NET_DETECT);
13305 	if (!nd)
13306 		return -ENOBUFS;
13307 
13308 	if (req->n_scan_plans == 1 &&
13309 	    nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_INTERVAL,
13310 			req->scan_plans[0].interval * 1000))
13311 		return -ENOBUFS;
13312 
13313 	if (nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_DELAY, req->delay))
13314 		return -ENOBUFS;
13315 
13316 	if (req->relative_rssi_set) {
13317 		struct nl80211_bss_select_rssi_adjust rssi_adjust;
13318 
13319 		if (nla_put_s8(msg, NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI,
13320 			       req->relative_rssi))
13321 			return -ENOBUFS;
13322 
13323 		rssi_adjust.band = req->rssi_adjust.band;
13324 		rssi_adjust.delta = req->rssi_adjust.delta;
13325 		if (nla_put(msg, NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST,
13326 			    sizeof(rssi_adjust), &rssi_adjust))
13327 			return -ENOBUFS;
13328 	}
13329 
13330 	freqs = nla_nest_start_noflag(msg, NL80211_ATTR_SCAN_FREQUENCIES);
13331 	if (!freqs)
13332 		return -ENOBUFS;
13333 
13334 	for (i = 0; i < req->n_channels; i++) {
13335 		if (nla_put_u32(msg, i, req->channels[i]->center_freq))
13336 			return -ENOBUFS;
13337 	}
13338 
13339 	nla_nest_end(msg, freqs);
13340 
13341 	if (req->n_match_sets) {
13342 		matches = nla_nest_start_noflag(msg,
13343 						NL80211_ATTR_SCHED_SCAN_MATCH);
13344 		if (!matches)
13345 			return -ENOBUFS;
13346 
13347 		for (i = 0; i < req->n_match_sets; i++) {
13348 			match = nla_nest_start_noflag(msg, i);
13349 			if (!match)
13350 				return -ENOBUFS;
13351 
13352 			if (nla_put(msg, NL80211_SCHED_SCAN_MATCH_ATTR_SSID,
13353 				    req->match_sets[i].ssid.ssid_len,
13354 				    req->match_sets[i].ssid.ssid))
13355 				return -ENOBUFS;
13356 			nla_nest_end(msg, match);
13357 		}
13358 		nla_nest_end(msg, matches);
13359 	}
13360 
13361 	scan_plans = nla_nest_start_noflag(msg, NL80211_ATTR_SCHED_SCAN_PLANS);
13362 	if (!scan_plans)
13363 		return -ENOBUFS;
13364 
13365 	for (i = 0; i < req->n_scan_plans; i++) {
13366 		scan_plan = nla_nest_start_noflag(msg, i + 1);
13367 		if (!scan_plan)
13368 			return -ENOBUFS;
13369 
13370 		if (nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_INTERVAL,
13371 				req->scan_plans[i].interval) ||
13372 		    (req->scan_plans[i].iterations &&
13373 		     nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_ITERATIONS,
13374 				 req->scan_plans[i].iterations)))
13375 			return -ENOBUFS;
13376 		nla_nest_end(msg, scan_plan);
13377 	}
13378 	nla_nest_end(msg, scan_plans);
13379 
13380 	nla_nest_end(msg, nd);
13381 
13382 	return 0;
13383 }
13384 
nl80211_get_wowlan(struct sk_buff * skb,struct genl_info * info)13385 static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
13386 {
13387 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
13388 	struct sk_buff *msg;
13389 	void *hdr;
13390 	u32 size = NLMSG_DEFAULT_SIZE;
13391 
13392 	if (!rdev->wiphy.wowlan)
13393 		return -EOPNOTSUPP;
13394 
13395 	if (rdev->wiphy.wowlan_config && rdev->wiphy.wowlan_config->tcp) {
13396 		/* adjust size to have room for all the data */
13397 		size += rdev->wiphy.wowlan_config->tcp->tokens_size +
13398 			rdev->wiphy.wowlan_config->tcp->payload_len +
13399 			rdev->wiphy.wowlan_config->tcp->wake_len +
13400 			rdev->wiphy.wowlan_config->tcp->wake_len / 8;
13401 	}
13402 
13403 	msg = nlmsg_new(size, GFP_KERNEL);
13404 	if (!msg)
13405 		return -ENOMEM;
13406 
13407 	hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
13408 			     NL80211_CMD_GET_WOWLAN);
13409 	if (!hdr)
13410 		goto nla_put_failure;
13411 
13412 	if (rdev->wiphy.wowlan_config) {
13413 		struct nlattr *nl_wowlan;
13414 
13415 		nl_wowlan = nla_nest_start_noflag(msg,
13416 						  NL80211_ATTR_WOWLAN_TRIGGERS);
13417 		if (!nl_wowlan)
13418 			goto nla_put_failure;
13419 
13420 		if ((rdev->wiphy.wowlan_config->any &&
13421 		     nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
13422 		    (rdev->wiphy.wowlan_config->disconnect &&
13423 		     nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
13424 		    (rdev->wiphy.wowlan_config->magic_pkt &&
13425 		     nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
13426 		    (rdev->wiphy.wowlan_config->gtk_rekey_failure &&
13427 		     nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
13428 		    (rdev->wiphy.wowlan_config->eap_identity_req &&
13429 		     nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
13430 		    (rdev->wiphy.wowlan_config->four_way_handshake &&
13431 		     nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
13432 		    (rdev->wiphy.wowlan_config->rfkill_release &&
13433 		     nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
13434 			goto nla_put_failure;
13435 
13436 		if (nl80211_send_wowlan_patterns(msg, rdev))
13437 			goto nla_put_failure;
13438 
13439 		if (nl80211_send_wowlan_tcp(msg,
13440 					    rdev->wiphy.wowlan_config->tcp))
13441 			goto nla_put_failure;
13442 
13443 		if (nl80211_send_wowlan_nd(
13444 			    msg,
13445 			    rdev->wiphy.wowlan_config->nd_config))
13446 			goto nla_put_failure;
13447 
13448 		nla_nest_end(msg, nl_wowlan);
13449 	}
13450 
13451 	genlmsg_end(msg, hdr);
13452 	return genlmsg_reply(msg, info);
13453 
13454 nla_put_failure:
13455 	nlmsg_free(msg);
13456 	return -ENOBUFS;
13457 }
13458 
nl80211_parse_wowlan_tcp(struct cfg80211_registered_device * rdev,struct nlattr * attr,struct cfg80211_wowlan * trig)13459 static int nl80211_parse_wowlan_tcp(struct cfg80211_registered_device *rdev,
13460 				    struct nlattr *attr,
13461 				    struct cfg80211_wowlan *trig)
13462 {
13463 	struct nlattr *tb[NUM_NL80211_WOWLAN_TCP];
13464 	struct cfg80211_wowlan_tcp *cfg;
13465 	struct nl80211_wowlan_tcp_data_token *tok = NULL;
13466 	struct nl80211_wowlan_tcp_data_seq *seq = NULL;
13467 	u32 size;
13468 	u32 data_size, wake_size, tokens_size = 0, wake_mask_size;
13469 	int err, port;
13470 
13471 	if (!rdev->wiphy.wowlan->tcp)
13472 		return -EINVAL;
13473 
13474 	err = nla_parse_nested_deprecated(tb, MAX_NL80211_WOWLAN_TCP, attr,
13475 					  nl80211_wowlan_tcp_policy, NULL);
13476 	if (err)
13477 		return err;
13478 
13479 	if (!tb[NL80211_WOWLAN_TCP_SRC_IPV4] ||
13480 	    !tb[NL80211_WOWLAN_TCP_DST_IPV4] ||
13481 	    !tb[NL80211_WOWLAN_TCP_DST_MAC] ||
13482 	    !tb[NL80211_WOWLAN_TCP_DST_PORT] ||
13483 	    !tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD] ||
13484 	    !tb[NL80211_WOWLAN_TCP_DATA_INTERVAL] ||
13485 	    !tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] ||
13486 	    !tb[NL80211_WOWLAN_TCP_WAKE_MASK])
13487 		return -EINVAL;
13488 
13489 	data_size = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]);
13490 	if (data_size > rdev->wiphy.wowlan->tcp->data_payload_max)
13491 		return -EINVAL;
13492 
13493 	if (nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) >
13494 			rdev->wiphy.wowlan->tcp->data_interval_max ||
13495 	    nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) == 0)
13496 		return -EINVAL;
13497 
13498 	wake_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]);
13499 	if (wake_size > rdev->wiphy.wowlan->tcp->wake_payload_max)
13500 		return -EINVAL;
13501 
13502 	wake_mask_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_MASK]);
13503 	if (wake_mask_size != DIV_ROUND_UP(wake_size, 8))
13504 		return -EINVAL;
13505 
13506 	if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]) {
13507 		u32 tokln = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
13508 
13509 		tok = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
13510 		tokens_size = tokln - sizeof(*tok);
13511 
13512 		if (!tok->len || tokens_size % tok->len)
13513 			return -EINVAL;
13514 		if (!rdev->wiphy.wowlan->tcp->tok)
13515 			return -EINVAL;
13516 		if (tok->len > rdev->wiphy.wowlan->tcp->tok->max_len)
13517 			return -EINVAL;
13518 		if (tok->len < rdev->wiphy.wowlan->tcp->tok->min_len)
13519 			return -EINVAL;
13520 		if (tokens_size > rdev->wiphy.wowlan->tcp->tok->bufsize)
13521 			return -EINVAL;
13522 		if (tok->offset + tok->len > data_size)
13523 			return -EINVAL;
13524 	}
13525 
13526 	if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]) {
13527 		seq = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]);
13528 		if (!rdev->wiphy.wowlan->tcp->seq)
13529 			return -EINVAL;
13530 		if (seq->len == 0 || seq->len > 4)
13531 			return -EINVAL;
13532 		if (seq->len + seq->offset > data_size)
13533 			return -EINVAL;
13534 	}
13535 
13536 	size = sizeof(*cfg);
13537 	size += data_size;
13538 	size += wake_size + wake_mask_size;
13539 	size += tokens_size;
13540 
13541 	cfg = kzalloc(size, GFP_KERNEL);
13542 	if (!cfg)
13543 		return -ENOMEM;
13544 	cfg->src = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_SRC_IPV4]);
13545 	cfg->dst = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_DST_IPV4]);
13546 	memcpy(cfg->dst_mac, nla_data(tb[NL80211_WOWLAN_TCP_DST_MAC]),
13547 	       ETH_ALEN);
13548 	if (tb[NL80211_WOWLAN_TCP_SRC_PORT])
13549 		port = nla_get_u16(tb[NL80211_WOWLAN_TCP_SRC_PORT]);
13550 	else
13551 		port = 0;
13552 #ifdef CONFIG_INET
13553 	/* allocate a socket and port for it and use it */
13554 	err = __sock_create(wiphy_net(&rdev->wiphy), PF_INET, SOCK_STREAM,
13555 			    IPPROTO_TCP, &cfg->sock, 1);
13556 	if (err) {
13557 		kfree(cfg);
13558 		return err;
13559 	}
13560 	if (inet_csk_get_port(cfg->sock->sk, port)) {
13561 		sock_release(cfg->sock);
13562 		kfree(cfg);
13563 		return -EADDRINUSE;
13564 	}
13565 	cfg->src_port = inet_sk(cfg->sock->sk)->inet_num;
13566 #else
13567 	if (!port) {
13568 		kfree(cfg);
13569 		return -EINVAL;
13570 	}
13571 	cfg->src_port = port;
13572 #endif
13573 
13574 	cfg->dst_port = nla_get_u16(tb[NL80211_WOWLAN_TCP_DST_PORT]);
13575 	cfg->payload_len = data_size;
13576 	cfg->payload = (u8 *)cfg + sizeof(*cfg) + tokens_size;
13577 	memcpy((void *)cfg->payload,
13578 	       nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]),
13579 	       data_size);
13580 	if (seq)
13581 		cfg->payload_seq = *seq;
13582 	cfg->data_interval = nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]);
13583 	cfg->wake_len = wake_size;
13584 	cfg->wake_data = (u8 *)cfg + sizeof(*cfg) + tokens_size + data_size;
13585 	memcpy((void *)cfg->wake_data,
13586 	       nla_data(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]),
13587 	       wake_size);
13588 	cfg->wake_mask = (u8 *)cfg + sizeof(*cfg) + tokens_size +
13589 			 data_size + wake_size;
13590 	memcpy((void *)cfg->wake_mask,
13591 	       nla_data(tb[NL80211_WOWLAN_TCP_WAKE_MASK]),
13592 	       wake_mask_size);
13593 	if (tok) {
13594 		cfg->tokens_size = tokens_size;
13595 		cfg->payload_tok = *tok;
13596 		memcpy(cfg->payload_tok.token_stream, tok->token_stream,
13597 		       tokens_size);
13598 	}
13599 
13600 	trig->tcp = cfg;
13601 
13602 	return 0;
13603 }
13604 
nl80211_parse_wowlan_nd(struct cfg80211_registered_device * rdev,const struct wiphy_wowlan_support * wowlan,struct nlattr * attr,struct cfg80211_wowlan * trig)13605 static int nl80211_parse_wowlan_nd(struct cfg80211_registered_device *rdev,
13606 				   const struct wiphy_wowlan_support *wowlan,
13607 				   struct nlattr *attr,
13608 				   struct cfg80211_wowlan *trig)
13609 {
13610 	struct nlattr **tb;
13611 	int err;
13612 
13613 	tb = kcalloc(NUM_NL80211_ATTR, sizeof(*tb), GFP_KERNEL);
13614 	if (!tb)
13615 		return -ENOMEM;
13616 
13617 	if (!(wowlan->flags & WIPHY_WOWLAN_NET_DETECT)) {
13618 		err = -EOPNOTSUPP;
13619 		goto out;
13620 	}
13621 
13622 	err = nla_parse_nested_deprecated(tb, NL80211_ATTR_MAX, attr,
13623 					  nl80211_policy, NULL);
13624 	if (err)
13625 		goto out;
13626 
13627 	trig->nd_config = nl80211_parse_sched_scan(&rdev->wiphy, NULL, tb,
13628 						   wowlan->max_nd_match_sets);
13629 	err = PTR_ERR_OR_ZERO(trig->nd_config);
13630 	if (err)
13631 		trig->nd_config = NULL;
13632 
13633 out:
13634 	kfree(tb);
13635 	return err;
13636 }
13637 
nl80211_set_wowlan(struct sk_buff * skb,struct genl_info * info)13638 static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
13639 {
13640 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
13641 	struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
13642 	struct cfg80211_wowlan new_triggers = {};
13643 	struct cfg80211_wowlan *ntrig;
13644 	const struct wiphy_wowlan_support *wowlan = rdev->wiphy.wowlan;
13645 	int err, i;
13646 	bool prev_enabled = rdev->wiphy.wowlan_config;
13647 	bool regular = false;
13648 
13649 	if (!wowlan)
13650 		return -EOPNOTSUPP;
13651 
13652 	if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
13653 		cfg80211_rdev_free_wowlan(rdev);
13654 		rdev->wiphy.wowlan_config = NULL;
13655 		goto set_wakeup;
13656 	}
13657 
13658 	err = nla_parse_nested_deprecated(tb, MAX_NL80211_WOWLAN_TRIG,
13659 					  info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS],
13660 					  nl80211_wowlan_policy, info->extack);
13661 	if (err)
13662 		return err;
13663 
13664 	if (tb[NL80211_WOWLAN_TRIG_ANY]) {
13665 		if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
13666 			return -EINVAL;
13667 		new_triggers.any = true;
13668 	}
13669 
13670 	if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
13671 		if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
13672 			return -EINVAL;
13673 		new_triggers.disconnect = true;
13674 		regular = true;
13675 	}
13676 
13677 	if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
13678 		if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
13679 			return -EINVAL;
13680 		new_triggers.magic_pkt = true;
13681 		regular = true;
13682 	}
13683 
13684 	if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
13685 		return -EINVAL;
13686 
13687 	if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
13688 		if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
13689 			return -EINVAL;
13690 		new_triggers.gtk_rekey_failure = true;
13691 		regular = true;
13692 	}
13693 
13694 	if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
13695 		if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
13696 			return -EINVAL;
13697 		new_triggers.eap_identity_req = true;
13698 		regular = true;
13699 	}
13700 
13701 	if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
13702 		if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
13703 			return -EINVAL;
13704 		new_triggers.four_way_handshake = true;
13705 		regular = true;
13706 	}
13707 
13708 	if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
13709 		if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
13710 			return -EINVAL;
13711 		new_triggers.rfkill_release = true;
13712 		regular = true;
13713 	}
13714 
13715 	if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
13716 		struct nlattr *pat;
13717 		int n_patterns = 0;
13718 		int rem, pat_len, mask_len, pkt_offset;
13719 		struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
13720 
13721 		regular = true;
13722 
13723 		nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
13724 				    rem)
13725 			n_patterns++;
13726 		if (n_patterns > wowlan->n_patterns)
13727 			return -EINVAL;
13728 
13729 		new_triggers.patterns = kcalloc(n_patterns,
13730 						sizeof(new_triggers.patterns[0]),
13731 						GFP_KERNEL);
13732 		if (!new_triggers.patterns)
13733 			return -ENOMEM;
13734 
13735 		new_triggers.n_patterns = n_patterns;
13736 		i = 0;
13737 
13738 		nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
13739 				    rem) {
13740 			u8 *mask_pat;
13741 
13742 			err = nla_parse_nested_deprecated(pat_tb,
13743 							  MAX_NL80211_PKTPAT,
13744 							  pat,
13745 							  nl80211_packet_pattern_policy,
13746 							  info->extack);
13747 			if (err)
13748 				goto error;
13749 
13750 			err = -EINVAL;
13751 			if (!pat_tb[NL80211_PKTPAT_MASK] ||
13752 			    !pat_tb[NL80211_PKTPAT_PATTERN])
13753 				goto error;
13754 			pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
13755 			mask_len = DIV_ROUND_UP(pat_len, 8);
13756 			if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
13757 				goto error;
13758 			if (pat_len > wowlan->pattern_max_len ||
13759 			    pat_len < wowlan->pattern_min_len)
13760 				goto error;
13761 
13762 			if (!pat_tb[NL80211_PKTPAT_OFFSET])
13763 				pkt_offset = 0;
13764 			else
13765 				pkt_offset = nla_get_u32(
13766 					pat_tb[NL80211_PKTPAT_OFFSET]);
13767 			if (pkt_offset > wowlan->max_pkt_offset)
13768 				goto error;
13769 			new_triggers.patterns[i].pkt_offset = pkt_offset;
13770 
13771 			mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL);
13772 			if (!mask_pat) {
13773 				err = -ENOMEM;
13774 				goto error;
13775 			}
13776 			new_triggers.patterns[i].mask = mask_pat;
13777 			memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]),
13778 			       mask_len);
13779 			mask_pat += mask_len;
13780 			new_triggers.patterns[i].pattern = mask_pat;
13781 			new_triggers.patterns[i].pattern_len = pat_len;
13782 			memcpy(mask_pat,
13783 			       nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
13784 			       pat_len);
13785 			i++;
13786 		}
13787 	}
13788 
13789 	if (tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION]) {
13790 		regular = true;
13791 		err = nl80211_parse_wowlan_tcp(
13792 			rdev, tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION],
13793 			&new_triggers);
13794 		if (err)
13795 			goto error;
13796 	}
13797 
13798 	if (tb[NL80211_WOWLAN_TRIG_NET_DETECT]) {
13799 		regular = true;
13800 		err = nl80211_parse_wowlan_nd(
13801 			rdev, wowlan, tb[NL80211_WOWLAN_TRIG_NET_DETECT],
13802 			&new_triggers);
13803 		if (err)
13804 			goto error;
13805 	}
13806 
13807 	/* The 'any' trigger means the device continues operating more or less
13808 	 * as in its normal operation mode and wakes up the host on most of the
13809 	 * normal interrupts (like packet RX, ...)
13810 	 * It therefore makes little sense to combine with the more constrained
13811 	 * wakeup trigger modes.
13812 	 */
13813 	if (new_triggers.any && regular) {
13814 		err = -EINVAL;
13815 		goto error;
13816 	}
13817 
13818 	ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
13819 	if (!ntrig) {
13820 		err = -ENOMEM;
13821 		goto error;
13822 	}
13823 	cfg80211_rdev_free_wowlan(rdev);
13824 	rdev->wiphy.wowlan_config = ntrig;
13825 
13826  set_wakeup:
13827 	if (rdev->ops->set_wakeup &&
13828 	    prev_enabled != !!rdev->wiphy.wowlan_config)
13829 		rdev_set_wakeup(rdev, rdev->wiphy.wowlan_config);
13830 
13831 	return 0;
13832  error:
13833 	for (i = 0; i < new_triggers.n_patterns; i++)
13834 		kfree(new_triggers.patterns[i].mask);
13835 	kfree(new_triggers.patterns);
13836 	if (new_triggers.tcp && new_triggers.tcp->sock)
13837 		sock_release(new_triggers.tcp->sock);
13838 	kfree(new_triggers.tcp);
13839 	kfree(new_triggers.nd_config);
13840 	return err;
13841 }
13842 #endif
13843 
nl80211_send_coalesce_rules(struct sk_buff * msg,struct cfg80211_registered_device * rdev)13844 static int nl80211_send_coalesce_rules(struct sk_buff *msg,
13845 				       struct cfg80211_registered_device *rdev)
13846 {
13847 	struct nlattr *nl_pats, *nl_pat, *nl_rule, *nl_rules;
13848 	int i, j, pat_len;
13849 	struct cfg80211_coalesce_rules *rule;
13850 
13851 	if (!rdev->coalesce->n_rules)
13852 		return 0;
13853 
13854 	nl_rules = nla_nest_start_noflag(msg, NL80211_ATTR_COALESCE_RULE);
13855 	if (!nl_rules)
13856 		return -ENOBUFS;
13857 
13858 	for (i = 0; i < rdev->coalesce->n_rules; i++) {
13859 		nl_rule = nla_nest_start_noflag(msg, i + 1);
13860 		if (!nl_rule)
13861 			return -ENOBUFS;
13862 
13863 		rule = &rdev->coalesce->rules[i];
13864 		if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_DELAY,
13865 				rule->delay))
13866 			return -ENOBUFS;
13867 
13868 		if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_CONDITION,
13869 				rule->condition))
13870 			return -ENOBUFS;
13871 
13872 		nl_pats = nla_nest_start_noflag(msg,
13873 						NL80211_ATTR_COALESCE_RULE_PKT_PATTERN);
13874 		if (!nl_pats)
13875 			return -ENOBUFS;
13876 
13877 		for (j = 0; j < rule->n_patterns; j++) {
13878 			nl_pat = nla_nest_start_noflag(msg, j + 1);
13879 			if (!nl_pat)
13880 				return -ENOBUFS;
13881 			pat_len = rule->patterns[j].pattern_len;
13882 			if (nla_put(msg, NL80211_PKTPAT_MASK,
13883 				    DIV_ROUND_UP(pat_len, 8),
13884 				    rule->patterns[j].mask) ||
13885 			    nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
13886 				    rule->patterns[j].pattern) ||
13887 			    nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
13888 					rule->patterns[j].pkt_offset))
13889 				return -ENOBUFS;
13890 			nla_nest_end(msg, nl_pat);
13891 		}
13892 		nla_nest_end(msg, nl_pats);
13893 		nla_nest_end(msg, nl_rule);
13894 	}
13895 	nla_nest_end(msg, nl_rules);
13896 
13897 	return 0;
13898 }
13899 
nl80211_get_coalesce(struct sk_buff * skb,struct genl_info * info)13900 static int nl80211_get_coalesce(struct sk_buff *skb, struct genl_info *info)
13901 {
13902 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
13903 	struct sk_buff *msg;
13904 	void *hdr;
13905 
13906 	if (!rdev->wiphy.coalesce)
13907 		return -EOPNOTSUPP;
13908 
13909 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
13910 	if (!msg)
13911 		return -ENOMEM;
13912 
13913 	hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
13914 			     NL80211_CMD_GET_COALESCE);
13915 	if (!hdr)
13916 		goto nla_put_failure;
13917 
13918 	if (rdev->coalesce && nl80211_send_coalesce_rules(msg, rdev))
13919 		goto nla_put_failure;
13920 
13921 	genlmsg_end(msg, hdr);
13922 	return genlmsg_reply(msg, info);
13923 
13924 nla_put_failure:
13925 	nlmsg_free(msg);
13926 	return -ENOBUFS;
13927 }
13928 
cfg80211_rdev_free_coalesce(struct cfg80211_registered_device * rdev)13929 void cfg80211_rdev_free_coalesce(struct cfg80211_registered_device *rdev)
13930 {
13931 	struct cfg80211_coalesce *coalesce = rdev->coalesce;
13932 	int i, j;
13933 	struct cfg80211_coalesce_rules *rule;
13934 
13935 	if (!coalesce)
13936 		return;
13937 
13938 	for (i = 0; i < coalesce->n_rules; i++) {
13939 		rule = &coalesce->rules[i];
13940 		for (j = 0; j < rule->n_patterns; j++)
13941 			kfree(rule->patterns[j].mask);
13942 		kfree(rule->patterns);
13943 	}
13944 	kfree(coalesce->rules);
13945 	kfree(coalesce);
13946 	rdev->coalesce = NULL;
13947 }
13948 
nl80211_parse_coalesce_rule(struct cfg80211_registered_device * rdev,struct nlattr * rule,struct cfg80211_coalesce_rules * new_rule)13949 static int nl80211_parse_coalesce_rule(struct cfg80211_registered_device *rdev,
13950 				       struct nlattr *rule,
13951 				       struct cfg80211_coalesce_rules *new_rule)
13952 {
13953 	int err, i;
13954 	const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
13955 	struct nlattr *tb[NUM_NL80211_ATTR_COALESCE_RULE], *pat;
13956 	int rem, pat_len, mask_len, pkt_offset, n_patterns = 0;
13957 	struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
13958 
13959 	err = nla_parse_nested_deprecated(tb, NL80211_ATTR_COALESCE_RULE_MAX,
13960 					  rule, nl80211_coalesce_policy, NULL);
13961 	if (err)
13962 		return err;
13963 
13964 	if (tb[NL80211_ATTR_COALESCE_RULE_DELAY])
13965 		new_rule->delay =
13966 			nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_DELAY]);
13967 	if (new_rule->delay > coalesce->max_delay)
13968 		return -EINVAL;
13969 
13970 	if (tb[NL80211_ATTR_COALESCE_RULE_CONDITION])
13971 		new_rule->condition =
13972 			nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_CONDITION]);
13973 
13974 	if (!tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN])
13975 		return -EINVAL;
13976 
13977 	nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
13978 			    rem)
13979 		n_patterns++;
13980 	if (n_patterns > coalesce->n_patterns)
13981 		return -EINVAL;
13982 
13983 	new_rule->patterns = kcalloc(n_patterns, sizeof(new_rule->patterns[0]),
13984 				     GFP_KERNEL);
13985 	if (!new_rule->patterns)
13986 		return -ENOMEM;
13987 
13988 	new_rule->n_patterns = n_patterns;
13989 	i = 0;
13990 
13991 	nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
13992 			    rem) {
13993 		u8 *mask_pat;
13994 
13995 		err = nla_parse_nested_deprecated(pat_tb, MAX_NL80211_PKTPAT,
13996 						  pat,
13997 						  nl80211_packet_pattern_policy,
13998 						  NULL);
13999 		if (err)
14000 			return err;
14001 
14002 		if (!pat_tb[NL80211_PKTPAT_MASK] ||
14003 		    !pat_tb[NL80211_PKTPAT_PATTERN])
14004 			return -EINVAL;
14005 		pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
14006 		mask_len = DIV_ROUND_UP(pat_len, 8);
14007 		if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
14008 			return -EINVAL;
14009 		if (pat_len > coalesce->pattern_max_len ||
14010 		    pat_len < coalesce->pattern_min_len)
14011 			return -EINVAL;
14012 
14013 		if (!pat_tb[NL80211_PKTPAT_OFFSET])
14014 			pkt_offset = 0;
14015 		else
14016 			pkt_offset = nla_get_u32(pat_tb[NL80211_PKTPAT_OFFSET]);
14017 		if (pkt_offset > coalesce->max_pkt_offset)
14018 			return -EINVAL;
14019 		new_rule->patterns[i].pkt_offset = pkt_offset;
14020 
14021 		mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL);
14022 		if (!mask_pat)
14023 			return -ENOMEM;
14024 
14025 		new_rule->patterns[i].mask = mask_pat;
14026 		memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]),
14027 		       mask_len);
14028 
14029 		mask_pat += mask_len;
14030 		new_rule->patterns[i].pattern = mask_pat;
14031 		new_rule->patterns[i].pattern_len = pat_len;
14032 		memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
14033 		       pat_len);
14034 		i++;
14035 	}
14036 
14037 	return 0;
14038 }
14039 
nl80211_set_coalesce(struct sk_buff * skb,struct genl_info * info)14040 static int nl80211_set_coalesce(struct sk_buff *skb, struct genl_info *info)
14041 {
14042 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14043 	const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
14044 	struct cfg80211_coalesce new_coalesce = {};
14045 	struct cfg80211_coalesce *n_coalesce;
14046 	int err, rem_rule, n_rules = 0, i, j;
14047 	struct nlattr *rule;
14048 	struct cfg80211_coalesce_rules *tmp_rule;
14049 
14050 	if (!rdev->wiphy.coalesce || !rdev->ops->set_coalesce)
14051 		return -EOPNOTSUPP;
14052 
14053 	if (!info->attrs[NL80211_ATTR_COALESCE_RULE]) {
14054 		cfg80211_rdev_free_coalesce(rdev);
14055 		rdev_set_coalesce(rdev, NULL);
14056 		return 0;
14057 	}
14058 
14059 	nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
14060 			    rem_rule)
14061 		n_rules++;
14062 	if (n_rules > coalesce->n_rules)
14063 		return -EINVAL;
14064 
14065 	new_coalesce.rules = kcalloc(n_rules, sizeof(new_coalesce.rules[0]),
14066 				     GFP_KERNEL);
14067 	if (!new_coalesce.rules)
14068 		return -ENOMEM;
14069 
14070 	new_coalesce.n_rules = n_rules;
14071 	i = 0;
14072 
14073 	nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
14074 			    rem_rule) {
14075 		err = nl80211_parse_coalesce_rule(rdev, rule,
14076 						  &new_coalesce.rules[i]);
14077 		if (err)
14078 			goto error;
14079 
14080 		i++;
14081 	}
14082 
14083 	err = rdev_set_coalesce(rdev, &new_coalesce);
14084 	if (err)
14085 		goto error;
14086 
14087 	n_coalesce = kmemdup(&new_coalesce, sizeof(new_coalesce), GFP_KERNEL);
14088 	if (!n_coalesce) {
14089 		err = -ENOMEM;
14090 		goto error;
14091 	}
14092 	cfg80211_rdev_free_coalesce(rdev);
14093 	rdev->coalesce = n_coalesce;
14094 
14095 	return 0;
14096 error:
14097 	for (i = 0; i < new_coalesce.n_rules; i++) {
14098 		tmp_rule = &new_coalesce.rules[i];
14099 		if (!tmp_rule)
14100 			continue;
14101 		for (j = 0; j < tmp_rule->n_patterns; j++)
14102 			kfree(tmp_rule->patterns[j].mask);
14103 		kfree(tmp_rule->patterns);
14104 	}
14105 	kfree(new_coalesce.rules);
14106 
14107 	return err;
14108 }
14109 
nl80211_set_rekey_data(struct sk_buff * skb,struct genl_info * info)14110 static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
14111 {
14112 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14113 	struct net_device *dev = info->user_ptr[1];
14114 	struct wireless_dev *wdev = dev->ieee80211_ptr;
14115 	struct nlattr *tb[NUM_NL80211_REKEY_DATA];
14116 	struct cfg80211_gtk_rekey_data rekey_data = {};
14117 	int err;
14118 
14119 	if (!info->attrs[NL80211_ATTR_REKEY_DATA])
14120 		return -EINVAL;
14121 
14122 	err = nla_parse_nested_deprecated(tb, MAX_NL80211_REKEY_DATA,
14123 					  info->attrs[NL80211_ATTR_REKEY_DATA],
14124 					  nl80211_rekey_policy, info->extack);
14125 	if (err)
14126 		return err;
14127 
14128 	if (!tb[NL80211_REKEY_DATA_REPLAY_CTR] || !tb[NL80211_REKEY_DATA_KEK] ||
14129 	    !tb[NL80211_REKEY_DATA_KCK])
14130 		return -EINVAL;
14131 	if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN &&
14132 	    !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_EXT_KEK_KCK &&
14133 	      nla_len(tb[NL80211_REKEY_DATA_KEK]) == NL80211_KEK_EXT_LEN))
14134 		return -ERANGE;
14135 	if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN &&
14136 	    !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_EXT_KEK_KCK &&
14137 	      nla_len(tb[NL80211_REKEY_DATA_KCK]) == NL80211_KCK_EXT_LEN) &&
14138 	     !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_EXT_KCK_32 &&
14139 	       nla_len(tb[NL80211_REKEY_DATA_KCK]) == NL80211_KCK_EXT_LEN_32))
14140 		return -ERANGE;
14141 
14142 	rekey_data.kek = nla_data(tb[NL80211_REKEY_DATA_KEK]);
14143 	rekey_data.kck = nla_data(tb[NL80211_REKEY_DATA_KCK]);
14144 	rekey_data.replay_ctr = nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]);
14145 	rekey_data.kek_len = nla_len(tb[NL80211_REKEY_DATA_KEK]);
14146 	rekey_data.kck_len = nla_len(tb[NL80211_REKEY_DATA_KCK]);
14147 	if (tb[NL80211_REKEY_DATA_AKM])
14148 		rekey_data.akm = nla_get_u32(tb[NL80211_REKEY_DATA_AKM]);
14149 
14150 	wdev_lock(wdev);
14151 	if (!wdev->connected) {
14152 		err = -ENOTCONN;
14153 		goto out;
14154 	}
14155 
14156 	if (!rdev->ops->set_rekey_data) {
14157 		err = -EOPNOTSUPP;
14158 		goto out;
14159 	}
14160 
14161 	err = rdev_set_rekey_data(rdev, dev, &rekey_data);
14162  out:
14163 	wdev_unlock(wdev);
14164 	return err;
14165 }
14166 
nl80211_register_unexpected_frame(struct sk_buff * skb,struct genl_info * info)14167 static int nl80211_register_unexpected_frame(struct sk_buff *skb,
14168 					     struct genl_info *info)
14169 {
14170 	struct net_device *dev = info->user_ptr[1];
14171 	struct wireless_dev *wdev = dev->ieee80211_ptr;
14172 
14173 	if (wdev->iftype != NL80211_IFTYPE_AP &&
14174 	    wdev->iftype != NL80211_IFTYPE_P2P_GO)
14175 		return -EINVAL;
14176 
14177 	if (wdev->ap_unexpected_nlportid)
14178 		return -EBUSY;
14179 
14180 	wdev->ap_unexpected_nlportid = info->snd_portid;
14181 	return 0;
14182 }
14183 
nl80211_probe_client(struct sk_buff * skb,struct genl_info * info)14184 static int nl80211_probe_client(struct sk_buff *skb,
14185 				struct genl_info *info)
14186 {
14187 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14188 	struct net_device *dev = info->user_ptr[1];
14189 	struct wireless_dev *wdev = dev->ieee80211_ptr;
14190 	struct sk_buff *msg;
14191 	void *hdr;
14192 	const u8 *addr;
14193 	u64 cookie;
14194 	int err;
14195 
14196 	if (wdev->iftype != NL80211_IFTYPE_AP &&
14197 	    wdev->iftype != NL80211_IFTYPE_P2P_GO)
14198 		return -EOPNOTSUPP;
14199 
14200 	if (!info->attrs[NL80211_ATTR_MAC])
14201 		return -EINVAL;
14202 
14203 	if (!rdev->ops->probe_client)
14204 		return -EOPNOTSUPP;
14205 
14206 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
14207 	if (!msg)
14208 		return -ENOMEM;
14209 
14210 	hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
14211 			     NL80211_CMD_PROBE_CLIENT);
14212 	if (!hdr) {
14213 		err = -ENOBUFS;
14214 		goto free_msg;
14215 	}
14216 
14217 	addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
14218 
14219 	err = rdev_probe_client(rdev, dev, addr, &cookie);
14220 	if (err)
14221 		goto free_msg;
14222 
14223 	if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
14224 			      NL80211_ATTR_PAD))
14225 		goto nla_put_failure;
14226 
14227 	genlmsg_end(msg, hdr);
14228 
14229 	return genlmsg_reply(msg, info);
14230 
14231  nla_put_failure:
14232 	err = -ENOBUFS;
14233  free_msg:
14234 	nlmsg_free(msg);
14235 	return err;
14236 }
14237 
nl80211_register_beacons(struct sk_buff * skb,struct genl_info * info)14238 static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
14239 {
14240 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14241 	struct cfg80211_beacon_registration *reg, *nreg;
14242 	int rv;
14243 
14244 	if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
14245 		return -EOPNOTSUPP;
14246 
14247 	nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
14248 	if (!nreg)
14249 		return -ENOMEM;
14250 
14251 	/* First, check if already registered. */
14252 	spin_lock_bh(&rdev->beacon_registrations_lock);
14253 	list_for_each_entry(reg, &rdev->beacon_registrations, list) {
14254 		if (reg->nlportid == info->snd_portid) {
14255 			rv = -EALREADY;
14256 			goto out_err;
14257 		}
14258 	}
14259 	/* Add it to the list */
14260 	nreg->nlportid = info->snd_portid;
14261 	list_add(&nreg->list, &rdev->beacon_registrations);
14262 
14263 	spin_unlock_bh(&rdev->beacon_registrations_lock);
14264 
14265 	return 0;
14266 out_err:
14267 	spin_unlock_bh(&rdev->beacon_registrations_lock);
14268 	kfree(nreg);
14269 	return rv;
14270 }
14271 
nl80211_start_p2p_device(struct sk_buff * skb,struct genl_info * info)14272 static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
14273 {
14274 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14275 	struct wireless_dev *wdev = info->user_ptr[1];
14276 	int err;
14277 
14278 	if (!rdev->ops->start_p2p_device)
14279 		return -EOPNOTSUPP;
14280 
14281 	if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
14282 		return -EOPNOTSUPP;
14283 
14284 	if (wdev_running(wdev))
14285 		return 0;
14286 
14287 	if (rfkill_blocked(rdev->wiphy.rfkill))
14288 		return -ERFKILL;
14289 
14290 	err = rdev_start_p2p_device(rdev, wdev);
14291 	if (err)
14292 		return err;
14293 
14294 	wdev->is_running = true;
14295 	rdev->opencount++;
14296 
14297 	return 0;
14298 }
14299 
nl80211_stop_p2p_device(struct sk_buff * skb,struct genl_info * info)14300 static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
14301 {
14302 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14303 	struct wireless_dev *wdev = info->user_ptr[1];
14304 
14305 	if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
14306 		return -EOPNOTSUPP;
14307 
14308 	if (!rdev->ops->stop_p2p_device)
14309 		return -EOPNOTSUPP;
14310 
14311 	cfg80211_stop_p2p_device(rdev, wdev);
14312 
14313 	return 0;
14314 }
14315 
nl80211_start_nan(struct sk_buff * skb,struct genl_info * info)14316 static int nl80211_start_nan(struct sk_buff *skb, struct genl_info *info)
14317 {
14318 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14319 	struct wireless_dev *wdev = info->user_ptr[1];
14320 	struct cfg80211_nan_conf conf = {};
14321 	int err;
14322 
14323 	if (wdev->iftype != NL80211_IFTYPE_NAN)
14324 		return -EOPNOTSUPP;
14325 
14326 	if (wdev_running(wdev))
14327 		return -EEXIST;
14328 
14329 	if (rfkill_blocked(rdev->wiphy.rfkill))
14330 		return -ERFKILL;
14331 
14332 	if (!info->attrs[NL80211_ATTR_NAN_MASTER_PREF])
14333 		return -EINVAL;
14334 
14335 	conf.master_pref =
14336 		nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]);
14337 
14338 	if (info->attrs[NL80211_ATTR_BANDS]) {
14339 		u32 bands = nla_get_u32(info->attrs[NL80211_ATTR_BANDS]);
14340 
14341 		if (bands & ~(u32)wdev->wiphy->nan_supported_bands)
14342 			return -EOPNOTSUPP;
14343 
14344 		if (bands && !(bands & BIT(NL80211_BAND_2GHZ)))
14345 			return -EINVAL;
14346 
14347 		conf.bands = bands;
14348 	}
14349 
14350 	err = rdev_start_nan(rdev, wdev, &conf);
14351 	if (err)
14352 		return err;
14353 
14354 	wdev->is_running = true;
14355 	rdev->opencount++;
14356 
14357 	return 0;
14358 }
14359 
nl80211_stop_nan(struct sk_buff * skb,struct genl_info * info)14360 static int nl80211_stop_nan(struct sk_buff *skb, struct genl_info *info)
14361 {
14362 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14363 	struct wireless_dev *wdev = info->user_ptr[1];
14364 
14365 	if (wdev->iftype != NL80211_IFTYPE_NAN)
14366 		return -EOPNOTSUPP;
14367 
14368 	cfg80211_stop_nan(rdev, wdev);
14369 
14370 	return 0;
14371 }
14372 
validate_nan_filter(struct nlattr * filter_attr)14373 static int validate_nan_filter(struct nlattr *filter_attr)
14374 {
14375 	struct nlattr *attr;
14376 	int len = 0, n_entries = 0, rem;
14377 
14378 	nla_for_each_nested(attr, filter_attr, rem) {
14379 		len += nla_len(attr);
14380 		n_entries++;
14381 	}
14382 
14383 	if (len >= U8_MAX)
14384 		return -EINVAL;
14385 
14386 	return n_entries;
14387 }
14388 
handle_nan_filter(struct nlattr * attr_filter,struct cfg80211_nan_func * func,bool tx)14389 static int handle_nan_filter(struct nlattr *attr_filter,
14390 			     struct cfg80211_nan_func *func,
14391 			     bool tx)
14392 {
14393 	struct nlattr *attr;
14394 	int n_entries, rem, i;
14395 	struct cfg80211_nan_func_filter *filter;
14396 
14397 	n_entries = validate_nan_filter(attr_filter);
14398 	if (n_entries < 0)
14399 		return n_entries;
14400 
14401 	BUILD_BUG_ON(sizeof(*func->rx_filters) != sizeof(*func->tx_filters));
14402 
14403 	filter = kcalloc(n_entries, sizeof(*func->rx_filters), GFP_KERNEL);
14404 	if (!filter)
14405 		return -ENOMEM;
14406 
14407 	i = 0;
14408 	nla_for_each_nested(attr, attr_filter, rem) {
14409 		filter[i].filter = nla_memdup(attr, GFP_KERNEL);
14410 		if (!filter[i].filter)
14411 			goto err;
14412 
14413 		filter[i].len = nla_len(attr);
14414 		i++;
14415 	}
14416 	if (tx) {
14417 		func->num_tx_filters = n_entries;
14418 		func->tx_filters = filter;
14419 	} else {
14420 		func->num_rx_filters = n_entries;
14421 		func->rx_filters = filter;
14422 	}
14423 
14424 	return 0;
14425 
14426 err:
14427 	i = 0;
14428 	nla_for_each_nested(attr, attr_filter, rem) {
14429 		kfree(filter[i].filter);
14430 		i++;
14431 	}
14432 	kfree(filter);
14433 	return -ENOMEM;
14434 }
14435 
nl80211_nan_add_func(struct sk_buff * skb,struct genl_info * info)14436 static int nl80211_nan_add_func(struct sk_buff *skb,
14437 				struct genl_info *info)
14438 {
14439 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14440 	struct wireless_dev *wdev = info->user_ptr[1];
14441 	struct nlattr *tb[NUM_NL80211_NAN_FUNC_ATTR], *func_attr;
14442 	struct cfg80211_nan_func *func;
14443 	struct sk_buff *msg = NULL;
14444 	void *hdr = NULL;
14445 	int err = 0;
14446 
14447 	if (wdev->iftype != NL80211_IFTYPE_NAN)
14448 		return -EOPNOTSUPP;
14449 
14450 	if (!wdev_running(wdev))
14451 		return -ENOTCONN;
14452 
14453 	if (!info->attrs[NL80211_ATTR_NAN_FUNC])
14454 		return -EINVAL;
14455 
14456 	err = nla_parse_nested_deprecated(tb, NL80211_NAN_FUNC_ATTR_MAX,
14457 					  info->attrs[NL80211_ATTR_NAN_FUNC],
14458 					  nl80211_nan_func_policy,
14459 					  info->extack);
14460 	if (err)
14461 		return err;
14462 
14463 	func = kzalloc(sizeof(*func), GFP_KERNEL);
14464 	if (!func)
14465 		return -ENOMEM;
14466 
14467 	func->cookie = cfg80211_assign_cookie(rdev);
14468 
14469 	if (!tb[NL80211_NAN_FUNC_TYPE]) {
14470 		err = -EINVAL;
14471 		goto out;
14472 	}
14473 
14474 
14475 	func->type = nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]);
14476 
14477 	if (!tb[NL80211_NAN_FUNC_SERVICE_ID]) {
14478 		err = -EINVAL;
14479 		goto out;
14480 	}
14481 
14482 	memcpy(func->service_id, nla_data(tb[NL80211_NAN_FUNC_SERVICE_ID]),
14483 	       sizeof(func->service_id));
14484 
14485 	func->close_range =
14486 		nla_get_flag(tb[NL80211_NAN_FUNC_CLOSE_RANGE]);
14487 
14488 	if (tb[NL80211_NAN_FUNC_SERVICE_INFO]) {
14489 		func->serv_spec_info_len =
14490 			nla_len(tb[NL80211_NAN_FUNC_SERVICE_INFO]);
14491 		func->serv_spec_info =
14492 			kmemdup(nla_data(tb[NL80211_NAN_FUNC_SERVICE_INFO]),
14493 				func->serv_spec_info_len,
14494 				GFP_KERNEL);
14495 		if (!func->serv_spec_info) {
14496 			err = -ENOMEM;
14497 			goto out;
14498 		}
14499 	}
14500 
14501 	if (tb[NL80211_NAN_FUNC_TTL])
14502 		func->ttl = nla_get_u32(tb[NL80211_NAN_FUNC_TTL]);
14503 
14504 	switch (func->type) {
14505 	case NL80211_NAN_FUNC_PUBLISH:
14506 		if (!tb[NL80211_NAN_FUNC_PUBLISH_TYPE]) {
14507 			err = -EINVAL;
14508 			goto out;
14509 		}
14510 
14511 		func->publish_type =
14512 			nla_get_u8(tb[NL80211_NAN_FUNC_PUBLISH_TYPE]);
14513 		func->publish_bcast =
14514 			nla_get_flag(tb[NL80211_NAN_FUNC_PUBLISH_BCAST]);
14515 
14516 		if ((!(func->publish_type & NL80211_NAN_SOLICITED_PUBLISH)) &&
14517 			func->publish_bcast) {
14518 			err = -EINVAL;
14519 			goto out;
14520 		}
14521 		break;
14522 	case NL80211_NAN_FUNC_SUBSCRIBE:
14523 		func->subscribe_active =
14524 			nla_get_flag(tb[NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE]);
14525 		break;
14526 	case NL80211_NAN_FUNC_FOLLOW_UP:
14527 		if (!tb[NL80211_NAN_FUNC_FOLLOW_UP_ID] ||
14528 		    !tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID] ||
14529 		    !tb[NL80211_NAN_FUNC_FOLLOW_UP_DEST]) {
14530 			err = -EINVAL;
14531 			goto out;
14532 		}
14533 
14534 		func->followup_id =
14535 			nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_ID]);
14536 		func->followup_reqid =
14537 			nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID]);
14538 		memcpy(func->followup_dest.addr,
14539 		       nla_data(tb[NL80211_NAN_FUNC_FOLLOW_UP_DEST]),
14540 		       sizeof(func->followup_dest.addr));
14541 		if (func->ttl) {
14542 			err = -EINVAL;
14543 			goto out;
14544 		}
14545 		break;
14546 	default:
14547 		err = -EINVAL;
14548 		goto out;
14549 	}
14550 
14551 	if (tb[NL80211_NAN_FUNC_SRF]) {
14552 		struct nlattr *srf_tb[NUM_NL80211_NAN_SRF_ATTR];
14553 
14554 		err = nla_parse_nested_deprecated(srf_tb,
14555 						  NL80211_NAN_SRF_ATTR_MAX,
14556 						  tb[NL80211_NAN_FUNC_SRF],
14557 						  nl80211_nan_srf_policy,
14558 						  info->extack);
14559 		if (err)
14560 			goto out;
14561 
14562 		func->srf_include =
14563 			nla_get_flag(srf_tb[NL80211_NAN_SRF_INCLUDE]);
14564 
14565 		if (srf_tb[NL80211_NAN_SRF_BF]) {
14566 			if (srf_tb[NL80211_NAN_SRF_MAC_ADDRS] ||
14567 			    !srf_tb[NL80211_NAN_SRF_BF_IDX]) {
14568 				err = -EINVAL;
14569 				goto out;
14570 			}
14571 
14572 			func->srf_bf_len =
14573 				nla_len(srf_tb[NL80211_NAN_SRF_BF]);
14574 			func->srf_bf =
14575 				kmemdup(nla_data(srf_tb[NL80211_NAN_SRF_BF]),
14576 					func->srf_bf_len, GFP_KERNEL);
14577 			if (!func->srf_bf) {
14578 				err = -ENOMEM;
14579 				goto out;
14580 			}
14581 
14582 			func->srf_bf_idx =
14583 				nla_get_u8(srf_tb[NL80211_NAN_SRF_BF_IDX]);
14584 		} else {
14585 			struct nlattr *attr, *mac_attr =
14586 				srf_tb[NL80211_NAN_SRF_MAC_ADDRS];
14587 			int n_entries, rem, i = 0;
14588 
14589 			if (!mac_attr) {
14590 				err = -EINVAL;
14591 				goto out;
14592 			}
14593 
14594 			n_entries = validate_acl_mac_addrs(mac_attr);
14595 			if (n_entries <= 0) {
14596 				err = -EINVAL;
14597 				goto out;
14598 			}
14599 
14600 			func->srf_num_macs = n_entries;
14601 			func->srf_macs =
14602 				kcalloc(n_entries, sizeof(*func->srf_macs),
14603 					GFP_KERNEL);
14604 			if (!func->srf_macs) {
14605 				err = -ENOMEM;
14606 				goto out;
14607 			}
14608 
14609 			nla_for_each_nested(attr, mac_attr, rem)
14610 				memcpy(func->srf_macs[i++].addr, nla_data(attr),
14611 				       sizeof(*func->srf_macs));
14612 		}
14613 	}
14614 
14615 	if (tb[NL80211_NAN_FUNC_TX_MATCH_FILTER]) {
14616 		err = handle_nan_filter(tb[NL80211_NAN_FUNC_TX_MATCH_FILTER],
14617 					func, true);
14618 		if (err)
14619 			goto out;
14620 	}
14621 
14622 	if (tb[NL80211_NAN_FUNC_RX_MATCH_FILTER]) {
14623 		err = handle_nan_filter(tb[NL80211_NAN_FUNC_RX_MATCH_FILTER],
14624 					func, false);
14625 		if (err)
14626 			goto out;
14627 	}
14628 
14629 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
14630 	if (!msg) {
14631 		err = -ENOMEM;
14632 		goto out;
14633 	}
14634 
14635 	hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
14636 			     NL80211_CMD_ADD_NAN_FUNCTION);
14637 	/* This can't really happen - we just allocated 4KB */
14638 	if (WARN_ON(!hdr)) {
14639 		err = -ENOMEM;
14640 		goto out;
14641 	}
14642 
14643 	err = rdev_add_nan_func(rdev, wdev, func);
14644 out:
14645 	if (err < 0) {
14646 		cfg80211_free_nan_func(func);
14647 		nlmsg_free(msg);
14648 		return err;
14649 	}
14650 
14651 	/* propagate the instance id and cookie to userspace  */
14652 	if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, func->cookie,
14653 			      NL80211_ATTR_PAD))
14654 		goto nla_put_failure;
14655 
14656 	func_attr = nla_nest_start_noflag(msg, NL80211_ATTR_NAN_FUNC);
14657 	if (!func_attr)
14658 		goto nla_put_failure;
14659 
14660 	if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID,
14661 		       func->instance_id))
14662 		goto nla_put_failure;
14663 
14664 	nla_nest_end(msg, func_attr);
14665 
14666 	genlmsg_end(msg, hdr);
14667 	return genlmsg_reply(msg, info);
14668 
14669 nla_put_failure:
14670 	nlmsg_free(msg);
14671 	return -ENOBUFS;
14672 }
14673 
nl80211_nan_del_func(struct sk_buff * skb,struct genl_info * info)14674 static int nl80211_nan_del_func(struct sk_buff *skb,
14675 			       struct genl_info *info)
14676 {
14677 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14678 	struct wireless_dev *wdev = info->user_ptr[1];
14679 	u64 cookie;
14680 
14681 	if (wdev->iftype != NL80211_IFTYPE_NAN)
14682 		return -EOPNOTSUPP;
14683 
14684 	if (!wdev_running(wdev))
14685 		return -ENOTCONN;
14686 
14687 	if (!info->attrs[NL80211_ATTR_COOKIE])
14688 		return -EINVAL;
14689 
14690 	cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
14691 
14692 	rdev_del_nan_func(rdev, wdev, cookie);
14693 
14694 	return 0;
14695 }
14696 
nl80211_nan_change_config(struct sk_buff * skb,struct genl_info * info)14697 static int nl80211_nan_change_config(struct sk_buff *skb,
14698 				     struct genl_info *info)
14699 {
14700 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14701 	struct wireless_dev *wdev = info->user_ptr[1];
14702 	struct cfg80211_nan_conf conf = {};
14703 	u32 changed = 0;
14704 
14705 	if (wdev->iftype != NL80211_IFTYPE_NAN)
14706 		return -EOPNOTSUPP;
14707 
14708 	if (!wdev_running(wdev))
14709 		return -ENOTCONN;
14710 
14711 	if (info->attrs[NL80211_ATTR_NAN_MASTER_PREF]) {
14712 		conf.master_pref =
14713 			nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]);
14714 		if (conf.master_pref <= 1 || conf.master_pref == 255)
14715 			return -EINVAL;
14716 
14717 		changed |= CFG80211_NAN_CONF_CHANGED_PREF;
14718 	}
14719 
14720 	if (info->attrs[NL80211_ATTR_BANDS]) {
14721 		u32 bands = nla_get_u32(info->attrs[NL80211_ATTR_BANDS]);
14722 
14723 		if (bands & ~(u32)wdev->wiphy->nan_supported_bands)
14724 			return -EOPNOTSUPP;
14725 
14726 		if (bands && !(bands & BIT(NL80211_BAND_2GHZ)))
14727 			return -EINVAL;
14728 
14729 		conf.bands = bands;
14730 		changed |= CFG80211_NAN_CONF_CHANGED_BANDS;
14731 	}
14732 
14733 	if (!changed)
14734 		return -EINVAL;
14735 
14736 	return rdev_nan_change_conf(rdev, wdev, &conf, changed);
14737 }
14738 
cfg80211_nan_match(struct wireless_dev * wdev,struct cfg80211_nan_match_params * match,gfp_t gfp)14739 void cfg80211_nan_match(struct wireless_dev *wdev,
14740 			struct cfg80211_nan_match_params *match, gfp_t gfp)
14741 {
14742 	struct wiphy *wiphy = wdev->wiphy;
14743 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
14744 	struct nlattr *match_attr, *local_func_attr, *peer_func_attr;
14745 	struct sk_buff *msg;
14746 	void *hdr;
14747 
14748 	if (WARN_ON(!match->inst_id || !match->peer_inst_id || !match->addr))
14749 		return;
14750 
14751 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
14752 	if (!msg)
14753 		return;
14754 
14755 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NAN_MATCH);
14756 	if (!hdr) {
14757 		nlmsg_free(msg);
14758 		return;
14759 	}
14760 
14761 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14762 	    (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
14763 					 wdev->netdev->ifindex)) ||
14764 	    nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
14765 			      NL80211_ATTR_PAD))
14766 		goto nla_put_failure;
14767 
14768 	if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, match->cookie,
14769 			      NL80211_ATTR_PAD) ||
14770 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, match->addr))
14771 		goto nla_put_failure;
14772 
14773 	match_attr = nla_nest_start_noflag(msg, NL80211_ATTR_NAN_MATCH);
14774 	if (!match_attr)
14775 		goto nla_put_failure;
14776 
14777 	local_func_attr = nla_nest_start_noflag(msg,
14778 						NL80211_NAN_MATCH_FUNC_LOCAL);
14779 	if (!local_func_attr)
14780 		goto nla_put_failure;
14781 
14782 	if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->inst_id))
14783 		goto nla_put_failure;
14784 
14785 	nla_nest_end(msg, local_func_attr);
14786 
14787 	peer_func_attr = nla_nest_start_noflag(msg,
14788 					       NL80211_NAN_MATCH_FUNC_PEER);
14789 	if (!peer_func_attr)
14790 		goto nla_put_failure;
14791 
14792 	if (nla_put_u8(msg, NL80211_NAN_FUNC_TYPE, match->type) ||
14793 	    nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->peer_inst_id))
14794 		goto nla_put_failure;
14795 
14796 	if (match->info && match->info_len &&
14797 	    nla_put(msg, NL80211_NAN_FUNC_SERVICE_INFO, match->info_len,
14798 		    match->info))
14799 		goto nla_put_failure;
14800 
14801 	nla_nest_end(msg, peer_func_attr);
14802 	nla_nest_end(msg, match_attr);
14803 	genlmsg_end(msg, hdr);
14804 
14805 	if (!wdev->owner_nlportid)
14806 		genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
14807 					msg, 0, NL80211_MCGRP_NAN, gfp);
14808 	else
14809 		genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
14810 				wdev->owner_nlportid);
14811 
14812 	return;
14813 
14814 nla_put_failure:
14815 	nlmsg_free(msg);
14816 }
14817 EXPORT_SYMBOL(cfg80211_nan_match);
14818 
cfg80211_nan_func_terminated(struct wireless_dev * wdev,u8 inst_id,enum nl80211_nan_func_term_reason reason,u64 cookie,gfp_t gfp)14819 void cfg80211_nan_func_terminated(struct wireless_dev *wdev,
14820 				  u8 inst_id,
14821 				  enum nl80211_nan_func_term_reason reason,
14822 				  u64 cookie, gfp_t gfp)
14823 {
14824 	struct wiphy *wiphy = wdev->wiphy;
14825 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
14826 	struct sk_buff *msg;
14827 	struct nlattr *func_attr;
14828 	void *hdr;
14829 
14830 	if (WARN_ON(!inst_id))
14831 		return;
14832 
14833 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
14834 	if (!msg)
14835 		return;
14836 
14837 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_NAN_FUNCTION);
14838 	if (!hdr) {
14839 		nlmsg_free(msg);
14840 		return;
14841 	}
14842 
14843 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14844 	    (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
14845 					 wdev->netdev->ifindex)) ||
14846 	    nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
14847 			      NL80211_ATTR_PAD))
14848 		goto nla_put_failure;
14849 
14850 	if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
14851 			      NL80211_ATTR_PAD))
14852 		goto nla_put_failure;
14853 
14854 	func_attr = nla_nest_start_noflag(msg, NL80211_ATTR_NAN_FUNC);
14855 	if (!func_attr)
14856 		goto nla_put_failure;
14857 
14858 	if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, inst_id) ||
14859 	    nla_put_u8(msg, NL80211_NAN_FUNC_TERM_REASON, reason))
14860 		goto nla_put_failure;
14861 
14862 	nla_nest_end(msg, func_attr);
14863 	genlmsg_end(msg, hdr);
14864 
14865 	if (!wdev->owner_nlportid)
14866 		genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
14867 					msg, 0, NL80211_MCGRP_NAN, gfp);
14868 	else
14869 		genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
14870 				wdev->owner_nlportid);
14871 
14872 	return;
14873 
14874 nla_put_failure:
14875 	nlmsg_free(msg);
14876 }
14877 EXPORT_SYMBOL(cfg80211_nan_func_terminated);
14878 
nl80211_get_protocol_features(struct sk_buff * skb,struct genl_info * info)14879 static int nl80211_get_protocol_features(struct sk_buff *skb,
14880 					 struct genl_info *info)
14881 {
14882 	void *hdr;
14883 	struct sk_buff *msg;
14884 
14885 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
14886 	if (!msg)
14887 		return -ENOMEM;
14888 
14889 	hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
14890 			     NL80211_CMD_GET_PROTOCOL_FEATURES);
14891 	if (!hdr)
14892 		goto nla_put_failure;
14893 
14894 	if (nla_put_u32(msg, NL80211_ATTR_PROTOCOL_FEATURES,
14895 			NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP))
14896 		goto nla_put_failure;
14897 
14898 	genlmsg_end(msg, hdr);
14899 	return genlmsg_reply(msg, info);
14900 
14901  nla_put_failure:
14902 	kfree_skb(msg);
14903 	return -ENOBUFS;
14904 }
14905 
nl80211_update_ft_ies(struct sk_buff * skb,struct genl_info * info)14906 static int nl80211_update_ft_ies(struct sk_buff *skb, struct genl_info *info)
14907 {
14908 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14909 	struct cfg80211_update_ft_ies_params ft_params;
14910 	struct net_device *dev = info->user_ptr[1];
14911 
14912 	if (!rdev->ops->update_ft_ies)
14913 		return -EOPNOTSUPP;
14914 
14915 	if (!info->attrs[NL80211_ATTR_MDID] ||
14916 	    !info->attrs[NL80211_ATTR_IE])
14917 		return -EINVAL;
14918 
14919 	memset(&ft_params, 0, sizeof(ft_params));
14920 	ft_params.md = nla_get_u16(info->attrs[NL80211_ATTR_MDID]);
14921 	ft_params.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
14922 	ft_params.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
14923 
14924 	return rdev_update_ft_ies(rdev, dev, &ft_params);
14925 }
14926 
nl80211_crit_protocol_start(struct sk_buff * skb,struct genl_info * info)14927 static int nl80211_crit_protocol_start(struct sk_buff *skb,
14928 				       struct genl_info *info)
14929 {
14930 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14931 	struct wireless_dev *wdev = info->user_ptr[1];
14932 	enum nl80211_crit_proto_id proto = NL80211_CRIT_PROTO_UNSPEC;
14933 	u16 duration;
14934 	int ret;
14935 
14936 	if (!rdev->ops->crit_proto_start)
14937 		return -EOPNOTSUPP;
14938 
14939 	if (WARN_ON(!rdev->ops->crit_proto_stop))
14940 		return -EINVAL;
14941 
14942 	if (rdev->crit_proto_nlportid)
14943 		return -EBUSY;
14944 
14945 	/* determine protocol if provided */
14946 	if (info->attrs[NL80211_ATTR_CRIT_PROT_ID])
14947 		proto = nla_get_u16(info->attrs[NL80211_ATTR_CRIT_PROT_ID]);
14948 
14949 	if (proto >= NUM_NL80211_CRIT_PROTO)
14950 		return -EINVAL;
14951 
14952 	/* timeout must be provided */
14953 	if (!info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION])
14954 		return -EINVAL;
14955 
14956 	duration =
14957 		nla_get_u16(info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]);
14958 
14959 	ret = rdev_crit_proto_start(rdev, wdev, proto, duration);
14960 	if (!ret)
14961 		rdev->crit_proto_nlportid = info->snd_portid;
14962 
14963 	return ret;
14964 }
14965 
nl80211_crit_protocol_stop(struct sk_buff * skb,struct genl_info * info)14966 static int nl80211_crit_protocol_stop(struct sk_buff *skb,
14967 				      struct genl_info *info)
14968 {
14969 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
14970 	struct wireless_dev *wdev = info->user_ptr[1];
14971 
14972 	if (!rdev->ops->crit_proto_stop)
14973 		return -EOPNOTSUPP;
14974 
14975 	if (rdev->crit_proto_nlportid) {
14976 		rdev->crit_proto_nlportid = 0;
14977 		rdev_crit_proto_stop(rdev, wdev);
14978 	}
14979 	return 0;
14980 }
14981 
nl80211_vendor_check_policy(const struct wiphy_vendor_command * vcmd,struct nlattr * attr,struct netlink_ext_ack * extack)14982 static int nl80211_vendor_check_policy(const struct wiphy_vendor_command *vcmd,
14983 				       struct nlattr *attr,
14984 				       struct netlink_ext_ack *extack)
14985 {
14986 	if (vcmd->policy == VENDOR_CMD_RAW_DATA) {
14987 		if (attr->nla_type & NLA_F_NESTED) {
14988 			NL_SET_ERR_MSG_ATTR(extack, attr,
14989 					    "unexpected nested data");
14990 			return -EINVAL;
14991 		}
14992 
14993 		return 0;
14994 	}
14995 
14996 	if (!(attr->nla_type & NLA_F_NESTED)) {
14997 		NL_SET_ERR_MSG_ATTR(extack, attr, "expected nested data");
14998 		return -EINVAL;
14999 	}
15000 
15001 	return nla_validate_nested(attr, vcmd->maxattr, vcmd->policy, extack);
15002 }
15003 
nl80211_vendor_cmd(struct sk_buff * skb,struct genl_info * info)15004 static int nl80211_vendor_cmd(struct sk_buff *skb, struct genl_info *info)
15005 {
15006 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15007 	struct wireless_dev *wdev =
15008 		__cfg80211_wdev_from_attrs(rdev, genl_info_net(info),
15009 					   info->attrs);
15010 	int i, err;
15011 	u32 vid, subcmd;
15012 
15013 	if (!rdev->wiphy.vendor_commands)
15014 		return -EOPNOTSUPP;
15015 
15016 	if (IS_ERR(wdev)) {
15017 		err = PTR_ERR(wdev);
15018 		if (err != -EINVAL)
15019 			return err;
15020 		wdev = NULL;
15021 	} else if (wdev->wiphy != &rdev->wiphy) {
15022 		return -EINVAL;
15023 	}
15024 
15025 	if (!info->attrs[NL80211_ATTR_VENDOR_ID] ||
15026 	    !info->attrs[NL80211_ATTR_VENDOR_SUBCMD])
15027 		return -EINVAL;
15028 
15029 	vid = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_ID]);
15030 	subcmd = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_SUBCMD]);
15031 	for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) {
15032 		const struct wiphy_vendor_command *vcmd;
15033 		void *data = NULL;
15034 		int len = 0;
15035 
15036 		vcmd = &rdev->wiphy.vendor_commands[i];
15037 
15038 		if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd)
15039 			continue;
15040 
15041 		if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV |
15042 				   WIPHY_VENDOR_CMD_NEED_NETDEV)) {
15043 			if (!wdev)
15044 				return -EINVAL;
15045 			if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV &&
15046 			    !wdev->netdev)
15047 				return -EINVAL;
15048 
15049 			if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) {
15050 				if (!wdev_running(wdev))
15051 					return -ENETDOWN;
15052 			}
15053 		} else {
15054 			wdev = NULL;
15055 		}
15056 
15057 		if (!vcmd->doit)
15058 			return -EOPNOTSUPP;
15059 
15060 		if (info->attrs[NL80211_ATTR_VENDOR_DATA]) {
15061 			data = nla_data(info->attrs[NL80211_ATTR_VENDOR_DATA]);
15062 			len = nla_len(info->attrs[NL80211_ATTR_VENDOR_DATA]);
15063 
15064 			err = nl80211_vendor_check_policy(vcmd,
15065 					info->attrs[NL80211_ATTR_VENDOR_DATA],
15066 					info->extack);
15067 			if (err)
15068 				return err;
15069 		}
15070 
15071 		rdev->cur_cmd_info = info;
15072 		err = vcmd->doit(&rdev->wiphy, wdev, data, len);
15073 		rdev->cur_cmd_info = NULL;
15074 		return err;
15075 	}
15076 
15077 	return -EOPNOTSUPP;
15078 }
15079 
nl80211_prepare_vendor_dump(struct sk_buff * skb,struct netlink_callback * cb,struct cfg80211_registered_device ** rdev,struct wireless_dev ** wdev)15080 static int nl80211_prepare_vendor_dump(struct sk_buff *skb,
15081 				       struct netlink_callback *cb,
15082 				       struct cfg80211_registered_device **rdev,
15083 				       struct wireless_dev **wdev)
15084 {
15085 	struct nlattr **attrbuf;
15086 	u32 vid, subcmd;
15087 	unsigned int i;
15088 	int vcmd_idx = -1;
15089 	int err;
15090 	void *data = NULL;
15091 	unsigned int data_len = 0;
15092 
15093 	if (cb->args[0]) {
15094 		/* subtract the 1 again here */
15095 		struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
15096 		struct wireless_dev *tmp;
15097 
15098 		if (!wiphy)
15099 			return -ENODEV;
15100 		*rdev = wiphy_to_rdev(wiphy);
15101 		*wdev = NULL;
15102 
15103 		if (cb->args[1]) {
15104 			list_for_each_entry(tmp, &wiphy->wdev_list, list) {
15105 				if (tmp->identifier == cb->args[1] - 1) {
15106 					*wdev = tmp;
15107 					break;
15108 				}
15109 			}
15110 		}
15111 
15112 		/* keep rtnl locked in successful case */
15113 		return 0;
15114 	}
15115 
15116 	attrbuf = kcalloc(NUM_NL80211_ATTR, sizeof(*attrbuf), GFP_KERNEL);
15117 	if (!attrbuf)
15118 		return -ENOMEM;
15119 
15120 	err = nlmsg_parse_deprecated(cb->nlh,
15121 				     GENL_HDRLEN + nl80211_fam.hdrsize,
15122 				     attrbuf, nl80211_fam.maxattr,
15123 				     nl80211_policy, NULL);
15124 	if (err)
15125 		goto out;
15126 
15127 	if (!attrbuf[NL80211_ATTR_VENDOR_ID] ||
15128 	    !attrbuf[NL80211_ATTR_VENDOR_SUBCMD]) {
15129 		err = -EINVAL;
15130 		goto out;
15131 	}
15132 
15133 	*wdev = __cfg80211_wdev_from_attrs(NULL, sock_net(skb->sk), attrbuf);
15134 	if (IS_ERR(*wdev))
15135 		*wdev = NULL;
15136 
15137 	*rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf);
15138 	if (IS_ERR(*rdev)) {
15139 		err = PTR_ERR(*rdev);
15140 		goto out;
15141 	}
15142 
15143 	vid = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_ID]);
15144 	subcmd = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_SUBCMD]);
15145 
15146 	for (i = 0; i < (*rdev)->wiphy.n_vendor_commands; i++) {
15147 		const struct wiphy_vendor_command *vcmd;
15148 
15149 		vcmd = &(*rdev)->wiphy.vendor_commands[i];
15150 
15151 		if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd)
15152 			continue;
15153 
15154 		if (!vcmd->dumpit) {
15155 			err = -EOPNOTSUPP;
15156 			goto out;
15157 		}
15158 
15159 		vcmd_idx = i;
15160 		break;
15161 	}
15162 
15163 	if (vcmd_idx < 0) {
15164 		err = -EOPNOTSUPP;
15165 		goto out;
15166 	}
15167 
15168 	if (attrbuf[NL80211_ATTR_VENDOR_DATA]) {
15169 		data = nla_data(attrbuf[NL80211_ATTR_VENDOR_DATA]);
15170 		data_len = nla_len(attrbuf[NL80211_ATTR_VENDOR_DATA]);
15171 
15172 		err = nl80211_vendor_check_policy(
15173 				&(*rdev)->wiphy.vendor_commands[vcmd_idx],
15174 				attrbuf[NL80211_ATTR_VENDOR_DATA],
15175 				cb->extack);
15176 		if (err)
15177 			goto out;
15178 	}
15179 
15180 	/* 0 is the first index - add 1 to parse only once */
15181 	cb->args[0] = (*rdev)->wiphy_idx + 1;
15182 	/* add 1 to know if it was NULL */
15183 	cb->args[1] = *wdev ? (*wdev)->identifier + 1 : 0;
15184 	cb->args[2] = vcmd_idx;
15185 	cb->args[3] = (unsigned long)data;
15186 	cb->args[4] = data_len;
15187 
15188 	/* keep rtnl locked in successful case */
15189 	err = 0;
15190 out:
15191 	kfree(attrbuf);
15192 	return err;
15193 }
15194 
nl80211_vendor_cmd_dump(struct sk_buff * skb,struct netlink_callback * cb)15195 static int nl80211_vendor_cmd_dump(struct sk_buff *skb,
15196 				   struct netlink_callback *cb)
15197 {
15198 	struct cfg80211_registered_device *rdev;
15199 	struct wireless_dev *wdev;
15200 	unsigned int vcmd_idx;
15201 	const struct wiphy_vendor_command *vcmd;
15202 	void *data;
15203 	int data_len;
15204 	int err;
15205 	struct nlattr *vendor_data;
15206 
15207 	rtnl_lock();
15208 	err = nl80211_prepare_vendor_dump(skb, cb, &rdev, &wdev);
15209 	if (err)
15210 		goto out;
15211 
15212 	vcmd_idx = cb->args[2];
15213 	data = (void *)cb->args[3];
15214 	data_len = cb->args[4];
15215 	vcmd = &rdev->wiphy.vendor_commands[vcmd_idx];
15216 
15217 	if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV |
15218 			   WIPHY_VENDOR_CMD_NEED_NETDEV)) {
15219 		if (!wdev) {
15220 			err = -EINVAL;
15221 			goto out;
15222 		}
15223 		if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV &&
15224 		    !wdev->netdev) {
15225 			err = -EINVAL;
15226 			goto out;
15227 		}
15228 
15229 		if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) {
15230 			if (!wdev_running(wdev)) {
15231 				err = -ENETDOWN;
15232 				goto out;
15233 			}
15234 		}
15235 	}
15236 
15237 	while (1) {
15238 		void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
15239 					   cb->nlh->nlmsg_seq, NLM_F_MULTI,
15240 					   NL80211_CMD_VENDOR);
15241 		if (!hdr)
15242 			break;
15243 
15244 		if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15245 		    (wdev && nla_put_u64_64bit(skb, NL80211_ATTR_WDEV,
15246 					       wdev_id(wdev),
15247 					       NL80211_ATTR_PAD))) {
15248 			genlmsg_cancel(skb, hdr);
15249 			break;
15250 		}
15251 
15252 		vendor_data = nla_nest_start_noflag(skb,
15253 						    NL80211_ATTR_VENDOR_DATA);
15254 		if (!vendor_data) {
15255 			genlmsg_cancel(skb, hdr);
15256 			break;
15257 		}
15258 
15259 		err = vcmd->dumpit(&rdev->wiphy, wdev, skb, data, data_len,
15260 				   (unsigned long *)&cb->args[5]);
15261 		nla_nest_end(skb, vendor_data);
15262 
15263 		if (err == -ENOBUFS || err == -ENOENT) {
15264 			genlmsg_cancel(skb, hdr);
15265 			break;
15266 		} else if (err <= 0) {
15267 			genlmsg_cancel(skb, hdr);
15268 			goto out;
15269 		}
15270 
15271 		genlmsg_end(skb, hdr);
15272 	}
15273 
15274 	err = skb->len;
15275  out:
15276 	rtnl_unlock();
15277 	return err;
15278 }
15279 
__cfg80211_alloc_reply_skb(struct wiphy * wiphy,enum nl80211_commands cmd,enum nl80211_attrs attr,int approxlen)15280 struct sk_buff *__cfg80211_alloc_reply_skb(struct wiphy *wiphy,
15281 					   enum nl80211_commands cmd,
15282 					   enum nl80211_attrs attr,
15283 					   int approxlen)
15284 {
15285 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
15286 
15287 	if (WARN_ON(!rdev->cur_cmd_info))
15288 		return NULL;
15289 
15290 	return __cfg80211_alloc_vendor_skb(rdev, NULL, approxlen,
15291 					   rdev->cur_cmd_info->snd_portid,
15292 					   rdev->cur_cmd_info->snd_seq,
15293 					   cmd, attr, NULL, GFP_KERNEL);
15294 }
15295 EXPORT_SYMBOL(__cfg80211_alloc_reply_skb);
15296 
cfg80211_vendor_cmd_reply(struct sk_buff * skb)15297 int cfg80211_vendor_cmd_reply(struct sk_buff *skb)
15298 {
15299 	struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
15300 	void *hdr = ((void **)skb->cb)[1];
15301 	struct nlattr *data = ((void **)skb->cb)[2];
15302 
15303 	/* clear CB data for netlink core to own from now on */
15304 	memset(skb->cb, 0, sizeof(skb->cb));
15305 
15306 	if (WARN_ON(!rdev->cur_cmd_info)) {
15307 		kfree_skb(skb);
15308 		return -EINVAL;
15309 	}
15310 
15311 	nla_nest_end(skb, data);
15312 	genlmsg_end(skb, hdr);
15313 	return genlmsg_reply(skb, rdev->cur_cmd_info);
15314 }
15315 EXPORT_SYMBOL_GPL(cfg80211_vendor_cmd_reply);
15316 
cfg80211_vendor_cmd_get_sender(struct wiphy * wiphy)15317 unsigned int cfg80211_vendor_cmd_get_sender(struct wiphy *wiphy)
15318 {
15319 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
15320 
15321 	if (WARN_ON(!rdev->cur_cmd_info))
15322 		return 0;
15323 
15324 	return rdev->cur_cmd_info->snd_portid;
15325 }
15326 EXPORT_SYMBOL_GPL(cfg80211_vendor_cmd_get_sender);
15327 
nl80211_set_qos_map(struct sk_buff * skb,struct genl_info * info)15328 static int nl80211_set_qos_map(struct sk_buff *skb,
15329 			       struct genl_info *info)
15330 {
15331 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15332 	struct cfg80211_qos_map *qos_map = NULL;
15333 	struct net_device *dev = info->user_ptr[1];
15334 	u8 *pos, len, num_des, des_len, des;
15335 	int ret;
15336 
15337 	if (!rdev->ops->set_qos_map)
15338 		return -EOPNOTSUPP;
15339 
15340 	if (info->attrs[NL80211_ATTR_QOS_MAP]) {
15341 		pos = nla_data(info->attrs[NL80211_ATTR_QOS_MAP]);
15342 		len = nla_len(info->attrs[NL80211_ATTR_QOS_MAP]);
15343 
15344 		if (len % 2)
15345 			return -EINVAL;
15346 
15347 		qos_map = kzalloc(sizeof(struct cfg80211_qos_map), GFP_KERNEL);
15348 		if (!qos_map)
15349 			return -ENOMEM;
15350 
15351 		num_des = (len - IEEE80211_QOS_MAP_LEN_MIN) >> 1;
15352 		if (num_des) {
15353 			des_len = num_des *
15354 				sizeof(struct cfg80211_dscp_exception);
15355 			memcpy(qos_map->dscp_exception, pos, des_len);
15356 			qos_map->num_des = num_des;
15357 			for (des = 0; des < num_des; des++) {
15358 				if (qos_map->dscp_exception[des].up > 7) {
15359 					kfree(qos_map);
15360 					return -EINVAL;
15361 				}
15362 			}
15363 			pos += des_len;
15364 		}
15365 		memcpy(qos_map->up, pos, IEEE80211_QOS_MAP_LEN_MIN);
15366 	}
15367 
15368 	wdev_lock(dev->ieee80211_ptr);
15369 	ret = nl80211_key_allowed(dev->ieee80211_ptr);
15370 	if (!ret)
15371 		ret = rdev_set_qos_map(rdev, dev, qos_map);
15372 	wdev_unlock(dev->ieee80211_ptr);
15373 
15374 	kfree(qos_map);
15375 	return ret;
15376 }
15377 
nl80211_add_tx_ts(struct sk_buff * skb,struct genl_info * info)15378 static int nl80211_add_tx_ts(struct sk_buff *skb, struct genl_info *info)
15379 {
15380 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15381 	struct net_device *dev = info->user_ptr[1];
15382 	struct wireless_dev *wdev = dev->ieee80211_ptr;
15383 	const u8 *peer;
15384 	u8 tsid, up;
15385 	u16 admitted_time = 0;
15386 	int err;
15387 
15388 	if (!(rdev->wiphy.features & NL80211_FEATURE_SUPPORTS_WMM_ADMISSION))
15389 		return -EOPNOTSUPP;
15390 
15391 	if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC] ||
15392 	    !info->attrs[NL80211_ATTR_USER_PRIO])
15393 		return -EINVAL;
15394 
15395 	tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]);
15396 	up = nla_get_u8(info->attrs[NL80211_ATTR_USER_PRIO]);
15397 
15398 	/* WMM uses TIDs 0-7 even for TSPEC */
15399 	if (tsid >= IEEE80211_FIRST_TSPEC_TSID) {
15400 		/* TODO: handle 802.11 TSPEC/admission control
15401 		 * need more attributes for that (e.g. BA session requirement);
15402 		 * change the WMM adminssion test above to allow both then
15403 		 */
15404 		return -EINVAL;
15405 	}
15406 
15407 	peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
15408 
15409 	if (info->attrs[NL80211_ATTR_ADMITTED_TIME]) {
15410 		admitted_time =
15411 			nla_get_u16(info->attrs[NL80211_ATTR_ADMITTED_TIME]);
15412 		if (!admitted_time)
15413 			return -EINVAL;
15414 	}
15415 
15416 	wdev_lock(wdev);
15417 	switch (wdev->iftype) {
15418 	case NL80211_IFTYPE_STATION:
15419 	case NL80211_IFTYPE_P2P_CLIENT:
15420 		if (wdev->connected)
15421 			break;
15422 		err = -ENOTCONN;
15423 		goto out;
15424 	default:
15425 		err = -EOPNOTSUPP;
15426 		goto out;
15427 	}
15428 
15429 	err = rdev_add_tx_ts(rdev, dev, tsid, peer, up, admitted_time);
15430 
15431  out:
15432 	wdev_unlock(wdev);
15433 	return err;
15434 }
15435 
nl80211_del_tx_ts(struct sk_buff * skb,struct genl_info * info)15436 static int nl80211_del_tx_ts(struct sk_buff *skb, struct genl_info *info)
15437 {
15438 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15439 	struct net_device *dev = info->user_ptr[1];
15440 	struct wireless_dev *wdev = dev->ieee80211_ptr;
15441 	const u8 *peer;
15442 	u8 tsid;
15443 	int err;
15444 
15445 	if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC])
15446 		return -EINVAL;
15447 
15448 	tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]);
15449 	peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
15450 
15451 	wdev_lock(wdev);
15452 	err = rdev_del_tx_ts(rdev, dev, tsid, peer);
15453 	wdev_unlock(wdev);
15454 
15455 	return err;
15456 }
15457 
nl80211_tdls_channel_switch(struct sk_buff * skb,struct genl_info * info)15458 static int nl80211_tdls_channel_switch(struct sk_buff *skb,
15459 				       struct genl_info *info)
15460 {
15461 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15462 	struct net_device *dev = info->user_ptr[1];
15463 	struct wireless_dev *wdev = dev->ieee80211_ptr;
15464 	struct cfg80211_chan_def chandef = {};
15465 	const u8 *addr;
15466 	u8 oper_class;
15467 	int err;
15468 
15469 	if (!rdev->ops->tdls_channel_switch ||
15470 	    !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
15471 		return -EOPNOTSUPP;
15472 
15473 	switch (dev->ieee80211_ptr->iftype) {
15474 	case NL80211_IFTYPE_STATION:
15475 	case NL80211_IFTYPE_P2P_CLIENT:
15476 		break;
15477 	default:
15478 		return -EOPNOTSUPP;
15479 	}
15480 
15481 	if (!info->attrs[NL80211_ATTR_MAC] ||
15482 	    !info->attrs[NL80211_ATTR_OPER_CLASS])
15483 		return -EINVAL;
15484 
15485 	err = nl80211_parse_chandef(rdev, info, &chandef);
15486 	if (err)
15487 		return err;
15488 
15489 	/*
15490 	 * Don't allow wide channels on the 2.4Ghz band, as per IEEE802.11-2012
15491 	 * section 10.22.6.2.1. Disallow 5/10Mhz channels as well for now, the
15492 	 * specification is not defined for them.
15493 	 */
15494 	if (chandef.chan->band == NL80211_BAND_2GHZ &&
15495 	    chandef.width != NL80211_CHAN_WIDTH_20_NOHT &&
15496 	    chandef.width != NL80211_CHAN_WIDTH_20)
15497 		return -EINVAL;
15498 
15499 	/* we will be active on the TDLS link */
15500 	if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef,
15501 					   wdev->iftype))
15502 		return -EINVAL;
15503 
15504 	/* don't allow switching to DFS channels */
15505 	if (cfg80211_chandef_dfs_required(wdev->wiphy, &chandef, wdev->iftype))
15506 		return -EINVAL;
15507 
15508 	addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
15509 	oper_class = nla_get_u8(info->attrs[NL80211_ATTR_OPER_CLASS]);
15510 
15511 	wdev_lock(wdev);
15512 	err = rdev_tdls_channel_switch(rdev, dev, addr, oper_class, &chandef);
15513 	wdev_unlock(wdev);
15514 
15515 	return err;
15516 }
15517 
nl80211_tdls_cancel_channel_switch(struct sk_buff * skb,struct genl_info * info)15518 static int nl80211_tdls_cancel_channel_switch(struct sk_buff *skb,
15519 					      struct genl_info *info)
15520 {
15521 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15522 	struct net_device *dev = info->user_ptr[1];
15523 	struct wireless_dev *wdev = dev->ieee80211_ptr;
15524 	const u8 *addr;
15525 
15526 	if (!rdev->ops->tdls_channel_switch ||
15527 	    !rdev->ops->tdls_cancel_channel_switch ||
15528 	    !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
15529 		return -EOPNOTSUPP;
15530 
15531 	switch (dev->ieee80211_ptr->iftype) {
15532 	case NL80211_IFTYPE_STATION:
15533 	case NL80211_IFTYPE_P2P_CLIENT:
15534 		break;
15535 	default:
15536 		return -EOPNOTSUPP;
15537 	}
15538 
15539 	if (!info->attrs[NL80211_ATTR_MAC])
15540 		return -EINVAL;
15541 
15542 	addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
15543 
15544 	wdev_lock(wdev);
15545 	rdev_tdls_cancel_channel_switch(rdev, dev, addr);
15546 	wdev_unlock(wdev);
15547 
15548 	return 0;
15549 }
15550 
nl80211_set_multicast_to_unicast(struct sk_buff * skb,struct genl_info * info)15551 static int nl80211_set_multicast_to_unicast(struct sk_buff *skb,
15552 					    struct genl_info *info)
15553 {
15554 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15555 	struct net_device *dev = info->user_ptr[1];
15556 	struct wireless_dev *wdev = dev->ieee80211_ptr;
15557 	const struct nlattr *nla;
15558 	bool enabled;
15559 
15560 	if (!rdev->ops->set_multicast_to_unicast)
15561 		return -EOPNOTSUPP;
15562 
15563 	if (wdev->iftype != NL80211_IFTYPE_AP &&
15564 	    wdev->iftype != NL80211_IFTYPE_P2P_GO)
15565 		return -EOPNOTSUPP;
15566 
15567 	nla = info->attrs[NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED];
15568 	enabled = nla_get_flag(nla);
15569 
15570 	return rdev_set_multicast_to_unicast(rdev, dev, enabled);
15571 }
15572 
nl80211_set_pmk(struct sk_buff * skb,struct genl_info * info)15573 static int nl80211_set_pmk(struct sk_buff *skb, struct genl_info *info)
15574 {
15575 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15576 	struct net_device *dev = info->user_ptr[1];
15577 	struct wireless_dev *wdev = dev->ieee80211_ptr;
15578 	struct cfg80211_pmk_conf pmk_conf = {};
15579 	int ret;
15580 
15581 	if (wdev->iftype != NL80211_IFTYPE_STATION &&
15582 	    wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
15583 		return -EOPNOTSUPP;
15584 
15585 	if (!wiphy_ext_feature_isset(&rdev->wiphy,
15586 				     NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X))
15587 		return -EOPNOTSUPP;
15588 
15589 	if (!info->attrs[NL80211_ATTR_MAC] || !info->attrs[NL80211_ATTR_PMK])
15590 		return -EINVAL;
15591 
15592 	wdev_lock(wdev);
15593 	if (!wdev->connected) {
15594 		ret = -ENOTCONN;
15595 		goto out;
15596 	}
15597 
15598 	pmk_conf.aa = nla_data(info->attrs[NL80211_ATTR_MAC]);
15599 	if (memcmp(pmk_conf.aa, wdev->u.client.connected_addr, ETH_ALEN)) {
15600 		ret = -EINVAL;
15601 		goto out;
15602 	}
15603 
15604 	pmk_conf.pmk = nla_data(info->attrs[NL80211_ATTR_PMK]);
15605 	pmk_conf.pmk_len = nla_len(info->attrs[NL80211_ATTR_PMK]);
15606 	if (pmk_conf.pmk_len != WLAN_PMK_LEN &&
15607 	    pmk_conf.pmk_len != WLAN_PMK_LEN_SUITE_B_192) {
15608 		ret = -EINVAL;
15609 		goto out;
15610 	}
15611 
15612 	if (info->attrs[NL80211_ATTR_PMKR0_NAME])
15613 		pmk_conf.pmk_r0_name =
15614 			nla_data(info->attrs[NL80211_ATTR_PMKR0_NAME]);
15615 
15616 	ret = rdev_set_pmk(rdev, dev, &pmk_conf);
15617 out:
15618 	wdev_unlock(wdev);
15619 	return ret;
15620 }
15621 
nl80211_del_pmk(struct sk_buff * skb,struct genl_info * info)15622 static int nl80211_del_pmk(struct sk_buff *skb, struct genl_info *info)
15623 {
15624 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15625 	struct net_device *dev = info->user_ptr[1];
15626 	struct wireless_dev *wdev = dev->ieee80211_ptr;
15627 	const u8 *aa;
15628 	int ret;
15629 
15630 	if (wdev->iftype != NL80211_IFTYPE_STATION &&
15631 	    wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
15632 		return -EOPNOTSUPP;
15633 
15634 	if (!wiphy_ext_feature_isset(&rdev->wiphy,
15635 				     NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X))
15636 		return -EOPNOTSUPP;
15637 
15638 	if (!info->attrs[NL80211_ATTR_MAC])
15639 		return -EINVAL;
15640 
15641 	wdev_lock(wdev);
15642 	aa = nla_data(info->attrs[NL80211_ATTR_MAC]);
15643 	ret = rdev_del_pmk(rdev, dev, aa);
15644 	wdev_unlock(wdev);
15645 
15646 	return ret;
15647 }
15648 
nl80211_external_auth(struct sk_buff * skb,struct genl_info * info)15649 static int nl80211_external_auth(struct sk_buff *skb, struct genl_info *info)
15650 {
15651 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15652 	struct net_device *dev = info->user_ptr[1];
15653 	struct cfg80211_external_auth_params params;
15654 
15655 	if (!rdev->ops->external_auth)
15656 		return -EOPNOTSUPP;
15657 
15658 	if (!info->attrs[NL80211_ATTR_SSID] &&
15659 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
15660 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
15661 		return -EINVAL;
15662 
15663 	if (!info->attrs[NL80211_ATTR_BSSID])
15664 		return -EINVAL;
15665 
15666 	if (!info->attrs[NL80211_ATTR_STATUS_CODE])
15667 		return -EINVAL;
15668 
15669 	memset(&params, 0, sizeof(params));
15670 
15671 	if (info->attrs[NL80211_ATTR_SSID]) {
15672 		params.ssid.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
15673 		if (params.ssid.ssid_len == 0)
15674 			return -EINVAL;
15675 		memcpy(params.ssid.ssid,
15676 		       nla_data(info->attrs[NL80211_ATTR_SSID]),
15677 		       params.ssid.ssid_len);
15678 	}
15679 
15680 	memcpy(params.bssid, nla_data(info->attrs[NL80211_ATTR_BSSID]),
15681 	       ETH_ALEN);
15682 
15683 	params.status = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
15684 
15685 	if (info->attrs[NL80211_ATTR_PMKID])
15686 		params.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
15687 
15688 	return rdev_external_auth(rdev, dev, &params);
15689 }
15690 
nl80211_tx_control_port(struct sk_buff * skb,struct genl_info * info)15691 static int nl80211_tx_control_port(struct sk_buff *skb, struct genl_info *info)
15692 {
15693 	bool dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
15694 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15695 	struct net_device *dev = info->user_ptr[1];
15696 	struct wireless_dev *wdev = dev->ieee80211_ptr;
15697 	const u8 *buf;
15698 	size_t len;
15699 	u8 *dest;
15700 	u16 proto;
15701 	bool noencrypt;
15702 	u64 cookie = 0;
15703 	int link_id;
15704 	int err;
15705 
15706 	if (!wiphy_ext_feature_isset(&rdev->wiphy,
15707 				     NL80211_EXT_FEATURE_CONTROL_PORT_OVER_NL80211))
15708 		return -EOPNOTSUPP;
15709 
15710 	if (!rdev->ops->tx_control_port)
15711 		return -EOPNOTSUPP;
15712 
15713 	if (!info->attrs[NL80211_ATTR_FRAME] ||
15714 	    !info->attrs[NL80211_ATTR_MAC] ||
15715 	    !info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
15716 		GENL_SET_ERR_MSG(info, "Frame, MAC or ethertype missing");
15717 		return -EINVAL;
15718 	}
15719 
15720 	wdev_lock(wdev);
15721 
15722 	switch (wdev->iftype) {
15723 	case NL80211_IFTYPE_AP:
15724 	case NL80211_IFTYPE_P2P_GO:
15725 	case NL80211_IFTYPE_MESH_POINT:
15726 		break;
15727 	case NL80211_IFTYPE_ADHOC:
15728 		if (wdev->u.ibss.current_bss)
15729 			break;
15730 		err = -ENOTCONN;
15731 		goto out;
15732 	case NL80211_IFTYPE_STATION:
15733 	case NL80211_IFTYPE_P2P_CLIENT:
15734 		if (wdev->connected)
15735 			break;
15736 		err = -ENOTCONN;
15737 		goto out;
15738 	default:
15739 		err = -EOPNOTSUPP;
15740 		goto out;
15741 	}
15742 
15743 	wdev_unlock(wdev);
15744 
15745 	buf = nla_data(info->attrs[NL80211_ATTR_FRAME]);
15746 	len = nla_len(info->attrs[NL80211_ATTR_FRAME]);
15747 	dest = nla_data(info->attrs[NL80211_ATTR_MAC]);
15748 	proto = nla_get_u16(info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
15749 	noencrypt =
15750 		nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT]);
15751 
15752 	link_id = nl80211_link_id_or_invalid(info->attrs);
15753 
15754 	err = rdev_tx_control_port(rdev, dev, buf, len,
15755 				   dest, cpu_to_be16(proto), noencrypt, link_id,
15756 				   dont_wait_for_ack ? NULL : &cookie);
15757 	if (!err && !dont_wait_for_ack)
15758 		nl_set_extack_cookie_u64(info->extack, cookie);
15759 	return err;
15760  out:
15761 	wdev_unlock(wdev);
15762 	return err;
15763 }
15764 
nl80211_get_ftm_responder_stats(struct sk_buff * skb,struct genl_info * info)15765 static int nl80211_get_ftm_responder_stats(struct sk_buff *skb,
15766 					   struct genl_info *info)
15767 {
15768 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15769 	struct net_device *dev = info->user_ptr[1];
15770 	struct wireless_dev *wdev = dev->ieee80211_ptr;
15771 	struct cfg80211_ftm_responder_stats ftm_stats = {};
15772 	unsigned int link_id = nl80211_link_id(info->attrs);
15773 	struct sk_buff *msg;
15774 	void *hdr;
15775 	struct nlattr *ftm_stats_attr;
15776 	int err;
15777 
15778 	if (wdev->iftype != NL80211_IFTYPE_AP ||
15779 	    !wdev->links[link_id].ap.beacon_interval)
15780 		return -EOPNOTSUPP;
15781 
15782 	err = rdev_get_ftm_responder_stats(rdev, dev, &ftm_stats);
15783 	if (err)
15784 		return err;
15785 
15786 	if (!ftm_stats.filled)
15787 		return -ENODATA;
15788 
15789 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
15790 	if (!msg)
15791 		return -ENOMEM;
15792 
15793 	hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
15794 			     NL80211_CMD_GET_FTM_RESPONDER_STATS);
15795 	if (!hdr)
15796 		goto nla_put_failure;
15797 
15798 	if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
15799 		goto nla_put_failure;
15800 
15801 	ftm_stats_attr = nla_nest_start_noflag(msg,
15802 					       NL80211_ATTR_FTM_RESPONDER_STATS);
15803 	if (!ftm_stats_attr)
15804 		goto nla_put_failure;
15805 
15806 #define SET_FTM(field, name, type)					 \
15807 	do { if ((ftm_stats.filled & BIT(NL80211_FTM_STATS_ ## name)) && \
15808 	    nla_put_ ## type(msg, NL80211_FTM_STATS_ ## name,		 \
15809 			     ftm_stats.field))				 \
15810 		goto nla_put_failure; } while (0)
15811 #define SET_FTM_U64(field, name)					 \
15812 	do { if ((ftm_stats.filled & BIT(NL80211_FTM_STATS_ ## name)) && \
15813 	    nla_put_u64_64bit(msg, NL80211_FTM_STATS_ ## name,		 \
15814 			      ftm_stats.field, NL80211_FTM_STATS_PAD))	 \
15815 		goto nla_put_failure; } while (0)
15816 
15817 	SET_FTM(success_num, SUCCESS_NUM, u32);
15818 	SET_FTM(partial_num, PARTIAL_NUM, u32);
15819 	SET_FTM(failed_num, FAILED_NUM, u32);
15820 	SET_FTM(asap_num, ASAP_NUM, u32);
15821 	SET_FTM(non_asap_num, NON_ASAP_NUM, u32);
15822 	SET_FTM_U64(total_duration_ms, TOTAL_DURATION_MSEC);
15823 	SET_FTM(unknown_triggers_num, UNKNOWN_TRIGGERS_NUM, u32);
15824 	SET_FTM(reschedule_requests_num, RESCHEDULE_REQUESTS_NUM, u32);
15825 	SET_FTM(out_of_window_triggers_num, OUT_OF_WINDOW_TRIGGERS_NUM, u32);
15826 #undef SET_FTM
15827 
15828 	nla_nest_end(msg, ftm_stats_attr);
15829 
15830 	genlmsg_end(msg, hdr);
15831 	return genlmsg_reply(msg, info);
15832 
15833 nla_put_failure:
15834 	nlmsg_free(msg);
15835 	return -ENOBUFS;
15836 }
15837 
nl80211_update_owe_info(struct sk_buff * skb,struct genl_info * info)15838 static int nl80211_update_owe_info(struct sk_buff *skb, struct genl_info *info)
15839 {
15840 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15841 	struct cfg80211_update_owe_info owe_info;
15842 	struct net_device *dev = info->user_ptr[1];
15843 
15844 	if (!rdev->ops->update_owe_info)
15845 		return -EOPNOTSUPP;
15846 
15847 	if (!info->attrs[NL80211_ATTR_STATUS_CODE] ||
15848 	    !info->attrs[NL80211_ATTR_MAC])
15849 		return -EINVAL;
15850 
15851 	memset(&owe_info, 0, sizeof(owe_info));
15852 	owe_info.status = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
15853 	nla_memcpy(owe_info.peer, info->attrs[NL80211_ATTR_MAC], ETH_ALEN);
15854 
15855 	if (info->attrs[NL80211_ATTR_IE]) {
15856 		owe_info.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
15857 		owe_info.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
15858 	}
15859 
15860 	return rdev_update_owe_info(rdev, dev, &owe_info);
15861 }
15862 
nl80211_probe_mesh_link(struct sk_buff * skb,struct genl_info * info)15863 static int nl80211_probe_mesh_link(struct sk_buff *skb, struct genl_info *info)
15864 {
15865 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
15866 	struct net_device *dev = info->user_ptr[1];
15867 	struct wireless_dev *wdev = dev->ieee80211_ptr;
15868 	struct station_info sinfo = {};
15869 	const u8 *buf;
15870 	size_t len;
15871 	u8 *dest;
15872 	int err;
15873 
15874 	if (!rdev->ops->probe_mesh_link || !rdev->ops->get_station)
15875 		return -EOPNOTSUPP;
15876 
15877 	if (!info->attrs[NL80211_ATTR_MAC] ||
15878 	    !info->attrs[NL80211_ATTR_FRAME]) {
15879 		GENL_SET_ERR_MSG(info, "Frame or MAC missing");
15880 		return -EINVAL;
15881 	}
15882 
15883 	if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
15884 		return -EOPNOTSUPP;
15885 
15886 	dest = nla_data(info->attrs[NL80211_ATTR_MAC]);
15887 	buf = nla_data(info->attrs[NL80211_ATTR_FRAME]);
15888 	len = nla_len(info->attrs[NL80211_ATTR_FRAME]);
15889 
15890 	if (len < sizeof(struct ethhdr))
15891 		return -EINVAL;
15892 
15893 	if (!ether_addr_equal(buf, dest) || is_multicast_ether_addr(buf) ||
15894 	    !ether_addr_equal(buf + ETH_ALEN, dev->dev_addr))
15895 		return -EINVAL;
15896 
15897 	err = rdev_get_station(rdev, dev, dest, &sinfo);
15898 	if (err)
15899 		return err;
15900 
15901 	cfg80211_sinfo_release_content(&sinfo);
15902 
15903 	return rdev_probe_mesh_link(rdev, dev, dest, buf, len);
15904 }
15905 
parse_tid_conf(struct cfg80211_registered_device * rdev,struct nlattr * attrs[],struct net_device * dev,struct cfg80211_tid_cfg * tid_conf,struct genl_info * info,const u8 * peer,unsigned int link_id)15906 static int parse_tid_conf(struct cfg80211_registered_device *rdev,
15907 			  struct nlattr *attrs[], struct net_device *dev,
15908 			  struct cfg80211_tid_cfg *tid_conf,
15909 			  struct genl_info *info, const u8 *peer,
15910 			  unsigned int link_id)
15911 {
15912 	struct netlink_ext_ack *extack = info->extack;
15913 	u64 mask;
15914 	int err;
15915 
15916 	if (!attrs[NL80211_TID_CONFIG_ATTR_TIDS])
15917 		return -EINVAL;
15918 
15919 	tid_conf->config_override =
15920 			nla_get_flag(attrs[NL80211_TID_CONFIG_ATTR_OVERRIDE]);
15921 	tid_conf->tids = nla_get_u16(attrs[NL80211_TID_CONFIG_ATTR_TIDS]);
15922 
15923 	if (tid_conf->config_override) {
15924 		if (rdev->ops->reset_tid_config) {
15925 			err = rdev_reset_tid_config(rdev, dev, peer,
15926 						    tid_conf->tids);
15927 			if (err)
15928 				return err;
15929 		} else {
15930 			return -EINVAL;
15931 		}
15932 	}
15933 
15934 	if (attrs[NL80211_TID_CONFIG_ATTR_NOACK]) {
15935 		tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_NOACK);
15936 		tid_conf->noack =
15937 			nla_get_u8(attrs[NL80211_TID_CONFIG_ATTR_NOACK]);
15938 	}
15939 
15940 	if (attrs[NL80211_TID_CONFIG_ATTR_RETRY_SHORT]) {
15941 		tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_RETRY_SHORT);
15942 		tid_conf->retry_short =
15943 			nla_get_u8(attrs[NL80211_TID_CONFIG_ATTR_RETRY_SHORT]);
15944 
15945 		if (tid_conf->retry_short > rdev->wiphy.max_data_retry_count)
15946 			return -EINVAL;
15947 	}
15948 
15949 	if (attrs[NL80211_TID_CONFIG_ATTR_RETRY_LONG]) {
15950 		tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_RETRY_LONG);
15951 		tid_conf->retry_long =
15952 			nla_get_u8(attrs[NL80211_TID_CONFIG_ATTR_RETRY_LONG]);
15953 
15954 		if (tid_conf->retry_long > rdev->wiphy.max_data_retry_count)
15955 			return -EINVAL;
15956 	}
15957 
15958 	if (attrs[NL80211_TID_CONFIG_ATTR_AMPDU_CTRL]) {
15959 		tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_AMPDU_CTRL);
15960 		tid_conf->ampdu =
15961 			nla_get_u8(attrs[NL80211_TID_CONFIG_ATTR_AMPDU_CTRL]);
15962 	}
15963 
15964 	if (attrs[NL80211_TID_CONFIG_ATTR_RTSCTS_CTRL]) {
15965 		tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_RTSCTS_CTRL);
15966 		tid_conf->rtscts =
15967 			nla_get_u8(attrs[NL80211_TID_CONFIG_ATTR_RTSCTS_CTRL]);
15968 	}
15969 
15970 	if (attrs[NL80211_TID_CONFIG_ATTR_AMSDU_CTRL]) {
15971 		tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_AMSDU_CTRL);
15972 		tid_conf->amsdu =
15973 			nla_get_u8(attrs[NL80211_TID_CONFIG_ATTR_AMSDU_CTRL]);
15974 	}
15975 
15976 	if (attrs[NL80211_TID_CONFIG_ATTR_TX_RATE_TYPE]) {
15977 		u32 idx = NL80211_TID_CONFIG_ATTR_TX_RATE_TYPE, attr;
15978 
15979 		tid_conf->txrate_type = nla_get_u8(attrs[idx]);
15980 
15981 		if (tid_conf->txrate_type != NL80211_TX_RATE_AUTOMATIC) {
15982 			attr = NL80211_TID_CONFIG_ATTR_TX_RATE;
15983 			err = nl80211_parse_tx_bitrate_mask(info, attrs, attr,
15984 						    &tid_conf->txrate_mask, dev,
15985 						    true, link_id);
15986 			if (err)
15987 				return err;
15988 
15989 			tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_TX_RATE);
15990 		}
15991 		tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_TX_RATE_TYPE);
15992 	}
15993 
15994 	if (peer)
15995 		mask = rdev->wiphy.tid_config_support.peer;
15996 	else
15997 		mask = rdev->wiphy.tid_config_support.vif;
15998 
15999 	if (tid_conf->mask & ~mask) {
16000 		NL_SET_ERR_MSG(extack, "unsupported TID configuration");
16001 		return -ENOTSUPP;
16002 	}
16003 
16004 	return 0;
16005 }
16006 
nl80211_set_tid_config(struct sk_buff * skb,struct genl_info * info)16007 static int nl80211_set_tid_config(struct sk_buff *skb,
16008 				  struct genl_info *info)
16009 {
16010 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
16011 	struct nlattr *attrs[NL80211_TID_CONFIG_ATTR_MAX + 1];
16012 	unsigned int link_id = nl80211_link_id(info->attrs);
16013 	struct net_device *dev = info->user_ptr[1];
16014 	struct cfg80211_tid_config *tid_config;
16015 	struct nlattr *tid;
16016 	int conf_idx = 0, rem_conf;
16017 	int ret = -EINVAL;
16018 	u32 num_conf = 0;
16019 
16020 	if (!info->attrs[NL80211_ATTR_TID_CONFIG])
16021 		return -EINVAL;
16022 
16023 	if (!rdev->ops->set_tid_config)
16024 		return -EOPNOTSUPP;
16025 
16026 	nla_for_each_nested(tid, info->attrs[NL80211_ATTR_TID_CONFIG],
16027 			    rem_conf)
16028 		num_conf++;
16029 
16030 	tid_config = kzalloc(struct_size(tid_config, tid_conf, num_conf),
16031 			     GFP_KERNEL);
16032 	if (!tid_config)
16033 		return -ENOMEM;
16034 
16035 	tid_config->n_tid_conf = num_conf;
16036 
16037 	if (info->attrs[NL80211_ATTR_MAC])
16038 		tid_config->peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
16039 
16040 	wdev_lock(dev->ieee80211_ptr);
16041 
16042 	nla_for_each_nested(tid, info->attrs[NL80211_ATTR_TID_CONFIG],
16043 			    rem_conf) {
16044 		ret = nla_parse_nested(attrs, NL80211_TID_CONFIG_ATTR_MAX,
16045 				       tid, NULL, NULL);
16046 
16047 		if (ret)
16048 			goto bad_tid_conf;
16049 
16050 		ret = parse_tid_conf(rdev, attrs, dev,
16051 				     &tid_config->tid_conf[conf_idx],
16052 				     info, tid_config->peer, link_id);
16053 		if (ret)
16054 			goto bad_tid_conf;
16055 
16056 		conf_idx++;
16057 	}
16058 
16059 	ret = rdev_set_tid_config(rdev, dev, tid_config);
16060 
16061 bad_tid_conf:
16062 	kfree(tid_config);
16063 	wdev_unlock(dev->ieee80211_ptr);
16064 	return ret;
16065 }
16066 
nl80211_color_change(struct sk_buff * skb,struct genl_info * info)16067 static int nl80211_color_change(struct sk_buff *skb, struct genl_info *info)
16068 {
16069 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
16070 	struct cfg80211_color_change_settings params = {};
16071 	struct net_device *dev = info->user_ptr[1];
16072 	struct wireless_dev *wdev = dev->ieee80211_ptr;
16073 	struct nlattr **tb;
16074 	u16 offset;
16075 	int err;
16076 
16077 	if (!rdev->ops->color_change)
16078 		return -EOPNOTSUPP;
16079 
16080 	if (!wiphy_ext_feature_isset(&rdev->wiphy,
16081 				     NL80211_EXT_FEATURE_BSS_COLOR))
16082 		return -EOPNOTSUPP;
16083 
16084 	if (wdev->iftype != NL80211_IFTYPE_AP)
16085 		return -EOPNOTSUPP;
16086 
16087 	if (!info->attrs[NL80211_ATTR_COLOR_CHANGE_COUNT] ||
16088 	    !info->attrs[NL80211_ATTR_COLOR_CHANGE_COLOR] ||
16089 	    !info->attrs[NL80211_ATTR_COLOR_CHANGE_ELEMS])
16090 		return -EINVAL;
16091 
16092 	params.count = nla_get_u8(info->attrs[NL80211_ATTR_COLOR_CHANGE_COUNT]);
16093 	params.color = nla_get_u8(info->attrs[NL80211_ATTR_COLOR_CHANGE_COLOR]);
16094 
16095 	err = nl80211_parse_beacon(rdev, info->attrs, &params.beacon_next,
16096 				   info->extack);
16097 	if (err)
16098 		return err;
16099 
16100 	tb = kcalloc(NL80211_ATTR_MAX + 1, sizeof(*tb), GFP_KERNEL);
16101 	if (!tb)
16102 		return -ENOMEM;
16103 
16104 	err = nla_parse_nested(tb, NL80211_ATTR_MAX,
16105 			       info->attrs[NL80211_ATTR_COLOR_CHANGE_ELEMS],
16106 			       nl80211_policy, info->extack);
16107 	if (err)
16108 		goto out;
16109 
16110 	err = nl80211_parse_beacon(rdev, tb, &params.beacon_color_change,
16111 				   info->extack);
16112 	if (err)
16113 		goto out;
16114 
16115 	if (!tb[NL80211_ATTR_CNTDWN_OFFS_BEACON]) {
16116 		err = -EINVAL;
16117 		goto out;
16118 	}
16119 
16120 	if (nla_len(tb[NL80211_ATTR_CNTDWN_OFFS_BEACON]) != sizeof(u16)) {
16121 		err = -EINVAL;
16122 		goto out;
16123 	}
16124 
16125 	offset = nla_get_u16(tb[NL80211_ATTR_CNTDWN_OFFS_BEACON]);
16126 	if (offset >= params.beacon_color_change.tail_len) {
16127 		err = -EINVAL;
16128 		goto out;
16129 	}
16130 
16131 	if (params.beacon_color_change.tail[offset] != params.count) {
16132 		err = -EINVAL;
16133 		goto out;
16134 	}
16135 
16136 	params.counter_offset_beacon = offset;
16137 
16138 	if (tb[NL80211_ATTR_CNTDWN_OFFS_PRESP]) {
16139 		if (nla_len(tb[NL80211_ATTR_CNTDWN_OFFS_PRESP]) !=
16140 		    sizeof(u16)) {
16141 			err = -EINVAL;
16142 			goto out;
16143 		}
16144 
16145 		offset = nla_get_u16(tb[NL80211_ATTR_CNTDWN_OFFS_PRESP]);
16146 		if (offset >= params.beacon_color_change.probe_resp_len) {
16147 			err = -EINVAL;
16148 			goto out;
16149 		}
16150 
16151 		if (params.beacon_color_change.probe_resp[offset] !=
16152 		    params.count) {
16153 			err = -EINVAL;
16154 			goto out;
16155 		}
16156 
16157 		params.counter_offset_presp = offset;
16158 	}
16159 
16160 	wdev_lock(wdev);
16161 	err = rdev_color_change(rdev, dev, &params);
16162 	wdev_unlock(wdev);
16163 
16164 out:
16165 	kfree(params.beacon_next.mbssid_ies);
16166 	kfree(params.beacon_color_change.mbssid_ies);
16167 	kfree(params.beacon_next.rnr_ies);
16168 	kfree(params.beacon_color_change.rnr_ies);
16169 	kfree(tb);
16170 	return err;
16171 }
16172 
nl80211_set_fils_aad(struct sk_buff * skb,struct genl_info * info)16173 static int nl80211_set_fils_aad(struct sk_buff *skb,
16174 				struct genl_info *info)
16175 {
16176 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
16177 	struct net_device *dev = info->user_ptr[1];
16178 	struct cfg80211_fils_aad fils_aad = {};
16179 	u8 *nonces;
16180 
16181 	if (!info->attrs[NL80211_ATTR_MAC] ||
16182 	    !info->attrs[NL80211_ATTR_FILS_KEK] ||
16183 	    !info->attrs[NL80211_ATTR_FILS_NONCES])
16184 		return -EINVAL;
16185 
16186 	fils_aad.macaddr = nla_data(info->attrs[NL80211_ATTR_MAC]);
16187 	fils_aad.kek_len = nla_len(info->attrs[NL80211_ATTR_FILS_KEK]);
16188 	fils_aad.kek = nla_data(info->attrs[NL80211_ATTR_FILS_KEK]);
16189 	nonces = nla_data(info->attrs[NL80211_ATTR_FILS_NONCES]);
16190 	fils_aad.snonce = nonces;
16191 	fils_aad.anonce = nonces + FILS_NONCE_LEN;
16192 
16193 	return rdev_set_fils_aad(rdev, dev, &fils_aad);
16194 }
16195 
nl80211_add_link(struct sk_buff * skb,struct genl_info * info)16196 static int nl80211_add_link(struct sk_buff *skb, struct genl_info *info)
16197 {
16198 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
16199 	unsigned int link_id = nl80211_link_id(info->attrs);
16200 	struct net_device *dev = info->user_ptr[1];
16201 	struct wireless_dev *wdev = dev->ieee80211_ptr;
16202 	int ret;
16203 
16204 	if (!(wdev->wiphy->flags & WIPHY_FLAG_SUPPORTS_MLO))
16205 		return -EINVAL;
16206 
16207 	switch (wdev->iftype) {
16208 	case NL80211_IFTYPE_AP:
16209 		break;
16210 	default:
16211 		return -EINVAL;
16212 	}
16213 
16214 	if (!info->attrs[NL80211_ATTR_MAC] ||
16215 	    !is_valid_ether_addr(nla_data(info->attrs[NL80211_ATTR_MAC])))
16216 		return -EINVAL;
16217 
16218 	wdev_lock(wdev);
16219 	wdev->valid_links |= BIT(link_id);
16220 	ether_addr_copy(wdev->links[link_id].addr,
16221 			nla_data(info->attrs[NL80211_ATTR_MAC]));
16222 
16223 	ret = rdev_add_intf_link(rdev, wdev, link_id);
16224 	if (ret) {
16225 		wdev->valid_links &= ~BIT(link_id);
16226 		eth_zero_addr(wdev->links[link_id].addr);
16227 	}
16228 	wdev_unlock(wdev);
16229 
16230 	return ret;
16231 }
16232 
nl80211_remove_link(struct sk_buff * skb,struct genl_info * info)16233 static int nl80211_remove_link(struct sk_buff *skb, struct genl_info *info)
16234 {
16235 	unsigned int link_id = nl80211_link_id(info->attrs);
16236 	struct net_device *dev = info->user_ptr[1];
16237 	struct wireless_dev *wdev = dev->ieee80211_ptr;
16238 
16239 	/* cannot remove if there's no link */
16240 	if (!info->attrs[NL80211_ATTR_MLO_LINK_ID])
16241 		return -EINVAL;
16242 
16243 	switch (wdev->iftype) {
16244 	case NL80211_IFTYPE_AP:
16245 		break;
16246 	default:
16247 		return -EINVAL;
16248 	}
16249 
16250 	wdev_lock(wdev);
16251 	cfg80211_remove_link(wdev, link_id);
16252 	wdev_unlock(wdev);
16253 
16254 	return 0;
16255 }
16256 
16257 static int
nl80211_add_mod_link_station(struct sk_buff * skb,struct genl_info * info,bool add)16258 nl80211_add_mod_link_station(struct sk_buff *skb, struct genl_info *info,
16259 			     bool add)
16260 {
16261 	struct link_station_parameters params = {};
16262 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
16263 	struct net_device *dev = info->user_ptr[1];
16264 	int err;
16265 
16266 	if ((add && !rdev->ops->add_link_station) ||
16267 	    (!add && !rdev->ops->mod_link_station))
16268 		return -EOPNOTSUPP;
16269 
16270 	if (add && !info->attrs[NL80211_ATTR_MAC])
16271 		return -EINVAL;
16272 
16273 	if (!info->attrs[NL80211_ATTR_MLD_ADDR])
16274 		return -EINVAL;
16275 
16276 	if (add && !info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
16277 		return -EINVAL;
16278 
16279 	params.mld_mac = nla_data(info->attrs[NL80211_ATTR_MLD_ADDR]);
16280 
16281 	if (info->attrs[NL80211_ATTR_MAC]) {
16282 		params.link_mac = nla_data(info->attrs[NL80211_ATTR_MAC]);
16283 		if (!is_valid_ether_addr(params.link_mac))
16284 			return -EINVAL;
16285 	}
16286 
16287 	if (!info->attrs[NL80211_ATTR_MLO_LINK_ID])
16288 		return -EINVAL;
16289 
16290 	params.link_id = nla_get_u8(info->attrs[NL80211_ATTR_MLO_LINK_ID]);
16291 
16292 	if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
16293 		params.supported_rates =
16294 			nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
16295 		params.supported_rates_len =
16296 			nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
16297 	}
16298 
16299 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
16300 		params.ht_capa =
16301 			nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
16302 
16303 	if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
16304 		params.vht_capa =
16305 			nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
16306 
16307 	if (info->attrs[NL80211_ATTR_HE_CAPABILITY]) {
16308 		params.he_capa =
16309 			nla_data(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
16310 		params.he_capa_len =
16311 			nla_len(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
16312 
16313 		if (info->attrs[NL80211_ATTR_EHT_CAPABILITY]) {
16314 			params.eht_capa =
16315 				nla_data(info->attrs[NL80211_ATTR_EHT_CAPABILITY]);
16316 			params.eht_capa_len =
16317 				nla_len(info->attrs[NL80211_ATTR_EHT_CAPABILITY]);
16318 
16319 			if (!ieee80211_eht_capa_size_ok((const u8 *)params.he_capa,
16320 							(const u8 *)params.eht_capa,
16321 							params.eht_capa_len,
16322 							false))
16323 				return -EINVAL;
16324 		}
16325 	}
16326 
16327 	if (info->attrs[NL80211_ATTR_HE_6GHZ_CAPABILITY])
16328 		params.he_6ghz_capa =
16329 			nla_data(info->attrs[NL80211_ATTR_HE_6GHZ_CAPABILITY]);
16330 
16331 	if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) {
16332 		params.opmode_notif_used = true;
16333 		params.opmode_notif =
16334 			nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]);
16335 	}
16336 
16337 	err = nl80211_parse_sta_txpower_setting(info, &params.txpwr,
16338 						&params.txpwr_set);
16339 	if (err)
16340 		return err;
16341 
16342 	wdev_lock(dev->ieee80211_ptr);
16343 	if (add)
16344 		err = rdev_add_link_station(rdev, dev, &params);
16345 	else
16346 		err = rdev_mod_link_station(rdev, dev, &params);
16347 	wdev_unlock(dev->ieee80211_ptr);
16348 
16349 	return err;
16350 }
16351 
16352 static int
nl80211_add_link_station(struct sk_buff * skb,struct genl_info * info)16353 nl80211_add_link_station(struct sk_buff *skb, struct genl_info *info)
16354 {
16355 	return nl80211_add_mod_link_station(skb, info, true);
16356 }
16357 
16358 static int
nl80211_modify_link_station(struct sk_buff * skb,struct genl_info * info)16359 nl80211_modify_link_station(struct sk_buff *skb, struct genl_info *info)
16360 {
16361 	return nl80211_add_mod_link_station(skb, info, false);
16362 }
16363 
16364 static int
nl80211_remove_link_station(struct sk_buff * skb,struct genl_info * info)16365 nl80211_remove_link_station(struct sk_buff *skb, struct genl_info *info)
16366 {
16367 	struct link_station_del_parameters params = {};
16368 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
16369 	struct net_device *dev = info->user_ptr[1];
16370 	int ret;
16371 
16372 	if (!rdev->ops->del_link_station)
16373 		return -EOPNOTSUPP;
16374 
16375 	if (!info->attrs[NL80211_ATTR_MLD_ADDR] ||
16376 	    !info->attrs[NL80211_ATTR_MLO_LINK_ID])
16377 		return -EINVAL;
16378 
16379 	params.mld_mac = nla_data(info->attrs[NL80211_ATTR_MLD_ADDR]);
16380 	params.link_id = nla_get_u8(info->attrs[NL80211_ATTR_MLO_LINK_ID]);
16381 
16382 	wdev_lock(dev->ieee80211_ptr);
16383 	ret = rdev_del_link_station(rdev, dev, &params);
16384 	wdev_unlock(dev->ieee80211_ptr);
16385 
16386 	return ret;
16387 }
16388 
nl80211_set_hw_timestamp(struct sk_buff * skb,struct genl_info * info)16389 static int nl80211_set_hw_timestamp(struct sk_buff *skb,
16390 				    struct genl_info *info)
16391 {
16392 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
16393 	struct net_device *dev = info->user_ptr[1];
16394 	struct cfg80211_set_hw_timestamp hwts = {};
16395 
16396 	if (!rdev->wiphy.hw_timestamp_max_peers)
16397 		return -EOPNOTSUPP;
16398 
16399 	if (!info->attrs[NL80211_ATTR_MAC] &&
16400 	    rdev->wiphy.hw_timestamp_max_peers != CFG80211_HW_TIMESTAMP_ALL_PEERS)
16401 		return -EOPNOTSUPP;
16402 
16403 	if (info->attrs[NL80211_ATTR_MAC])
16404 		hwts.macaddr = nla_data(info->attrs[NL80211_ATTR_MAC]);
16405 
16406 	hwts.enable =
16407 		nla_get_flag(info->attrs[NL80211_ATTR_HW_TIMESTAMP_ENABLED]);
16408 
16409 	return rdev_set_hw_timestamp(rdev, dev, &hwts);
16410 }
16411 
16412 #define NL80211_FLAG_NEED_WIPHY		0x01
16413 #define NL80211_FLAG_NEED_NETDEV	0x02
16414 #define NL80211_FLAG_NEED_RTNL		0x04
16415 #define NL80211_FLAG_CHECK_NETDEV_UP	0x08
16416 #define NL80211_FLAG_NEED_NETDEV_UP	(NL80211_FLAG_NEED_NETDEV |\
16417 					 NL80211_FLAG_CHECK_NETDEV_UP)
16418 #define NL80211_FLAG_NEED_WDEV		0x10
16419 /* If a netdev is associated, it must be UP, P2P must be started */
16420 #define NL80211_FLAG_NEED_WDEV_UP	(NL80211_FLAG_NEED_WDEV |\
16421 					 NL80211_FLAG_CHECK_NETDEV_UP)
16422 #define NL80211_FLAG_CLEAR_SKB		0x20
16423 #define NL80211_FLAG_NO_WIPHY_MTX	0x40
16424 #define NL80211_FLAG_MLO_VALID_LINK_ID	0x80
16425 #define NL80211_FLAG_MLO_UNSUPPORTED	0x100
16426 
16427 #define INTERNAL_FLAG_SELECTORS(__sel)			\
16428 	SELECTOR(__sel, NONE, 0) /* must be first */	\
16429 	SELECTOR(__sel, WIPHY,				\
16430 		 NL80211_FLAG_NEED_WIPHY)		\
16431 	SELECTOR(__sel, WDEV,				\
16432 		 NL80211_FLAG_NEED_WDEV)		\
16433 	SELECTOR(__sel, NETDEV,				\
16434 		 NL80211_FLAG_NEED_NETDEV)		\
16435 	SELECTOR(__sel, NETDEV_LINK,			\
16436 		 NL80211_FLAG_NEED_NETDEV |		\
16437 		 NL80211_FLAG_MLO_VALID_LINK_ID)	\
16438 	SELECTOR(__sel, NETDEV_NO_MLO,			\
16439 		 NL80211_FLAG_NEED_NETDEV |		\
16440 		 NL80211_FLAG_MLO_UNSUPPORTED)	\
16441 	SELECTOR(__sel, WIPHY_RTNL,			\
16442 		 NL80211_FLAG_NEED_WIPHY |		\
16443 		 NL80211_FLAG_NEED_RTNL)		\
16444 	SELECTOR(__sel, WIPHY_RTNL_NOMTX,		\
16445 		 NL80211_FLAG_NEED_WIPHY |		\
16446 		 NL80211_FLAG_NEED_RTNL |		\
16447 		 NL80211_FLAG_NO_WIPHY_MTX)		\
16448 	SELECTOR(__sel, WDEV_RTNL,			\
16449 		 NL80211_FLAG_NEED_WDEV |		\
16450 		 NL80211_FLAG_NEED_RTNL)		\
16451 	SELECTOR(__sel, NETDEV_RTNL,			\
16452 		 NL80211_FLAG_NEED_NETDEV |		\
16453 		 NL80211_FLAG_NEED_RTNL)		\
16454 	SELECTOR(__sel, NETDEV_UP,			\
16455 		 NL80211_FLAG_NEED_NETDEV_UP)		\
16456 	SELECTOR(__sel, NETDEV_UP_LINK,			\
16457 		 NL80211_FLAG_NEED_NETDEV_UP |		\
16458 		 NL80211_FLAG_MLO_VALID_LINK_ID)	\
16459 	SELECTOR(__sel, NETDEV_UP_NO_MLO,		\
16460 		 NL80211_FLAG_NEED_NETDEV_UP |		\
16461 		 NL80211_FLAG_MLO_UNSUPPORTED)		\
16462 	SELECTOR(__sel, NETDEV_UP_NO_MLO_CLEAR,		\
16463 		 NL80211_FLAG_NEED_NETDEV_UP |		\
16464 		 NL80211_FLAG_CLEAR_SKB |		\
16465 		 NL80211_FLAG_MLO_UNSUPPORTED)		\
16466 	SELECTOR(__sel, NETDEV_UP_NOTMX,		\
16467 		 NL80211_FLAG_NEED_NETDEV_UP |		\
16468 		 NL80211_FLAG_NO_WIPHY_MTX)		\
16469 	SELECTOR(__sel, NETDEV_UP_NOTMX_NOMLO,		\
16470 		 NL80211_FLAG_NEED_NETDEV_UP |		\
16471 		 NL80211_FLAG_NO_WIPHY_MTX |		\
16472 		 NL80211_FLAG_MLO_UNSUPPORTED)		\
16473 	SELECTOR(__sel, NETDEV_UP_CLEAR,		\
16474 		 NL80211_FLAG_NEED_NETDEV_UP |		\
16475 		 NL80211_FLAG_CLEAR_SKB)		\
16476 	SELECTOR(__sel, WDEV_UP,			\
16477 		 NL80211_FLAG_NEED_WDEV_UP)		\
16478 	SELECTOR(__sel, WDEV_UP_LINK,			\
16479 		 NL80211_FLAG_NEED_WDEV_UP |		\
16480 		 NL80211_FLAG_MLO_VALID_LINK_ID)	\
16481 	SELECTOR(__sel, WDEV_UP_RTNL,			\
16482 		 NL80211_FLAG_NEED_WDEV_UP |		\
16483 		 NL80211_FLAG_NEED_RTNL)		\
16484 	SELECTOR(__sel, WIPHY_CLEAR,			\
16485 		 NL80211_FLAG_NEED_WIPHY |		\
16486 		 NL80211_FLAG_CLEAR_SKB)
16487 
16488 enum nl80211_internal_flags_selector {
16489 #define SELECTOR(_, name, value)	NL80211_IFL_SEL_##name,
16490 	INTERNAL_FLAG_SELECTORS(_)
16491 #undef SELECTOR
16492 };
16493 
16494 static u32 nl80211_internal_flags[] = {
16495 #define SELECTOR(_, name, value)	[NL80211_IFL_SEL_##name] = value,
16496 	INTERNAL_FLAG_SELECTORS(_)
16497 #undef SELECTOR
16498 };
16499 
nl80211_pre_doit(const struct genl_split_ops * ops,struct sk_buff * skb,struct genl_info * info)16500 static int nl80211_pre_doit(const struct genl_split_ops *ops,
16501 			    struct sk_buff *skb,
16502 			    struct genl_info *info)
16503 {
16504 	struct cfg80211_registered_device *rdev = NULL;
16505 	struct wireless_dev *wdev = NULL;
16506 	struct net_device *dev = NULL;
16507 	u32 internal_flags;
16508 	int err;
16509 
16510 	if (WARN_ON(ops->internal_flags >= ARRAY_SIZE(nl80211_internal_flags)))
16511 		return -EINVAL;
16512 
16513 	internal_flags = nl80211_internal_flags[ops->internal_flags];
16514 
16515 	rtnl_lock();
16516 	if (internal_flags & NL80211_FLAG_NEED_WIPHY) {
16517 		rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
16518 		if (IS_ERR(rdev)) {
16519 			err = PTR_ERR(rdev);
16520 			goto out_unlock;
16521 		}
16522 		info->user_ptr[0] = rdev;
16523 	} else if (internal_flags & NL80211_FLAG_NEED_NETDEV ||
16524 		   internal_flags & NL80211_FLAG_NEED_WDEV) {
16525 		wdev = __cfg80211_wdev_from_attrs(NULL, genl_info_net(info),
16526 						  info->attrs);
16527 		if (IS_ERR(wdev)) {
16528 			err = PTR_ERR(wdev);
16529 			goto out_unlock;
16530 		}
16531 
16532 		dev = wdev->netdev;
16533 		dev_hold(dev);
16534 		rdev = wiphy_to_rdev(wdev->wiphy);
16535 
16536 		if (internal_flags & NL80211_FLAG_NEED_NETDEV) {
16537 			if (!dev) {
16538 				err = -EINVAL;
16539 				goto out_unlock;
16540 			}
16541 
16542 			info->user_ptr[1] = dev;
16543 		} else {
16544 			info->user_ptr[1] = wdev;
16545 		}
16546 
16547 		if (internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
16548 		    !wdev_running(wdev)) {
16549 			err = -ENETDOWN;
16550 			goto out_unlock;
16551 		}
16552 
16553 		info->user_ptr[0] = rdev;
16554 	}
16555 
16556 	if (internal_flags & NL80211_FLAG_MLO_VALID_LINK_ID) {
16557 		struct nlattr *link_id = info->attrs[NL80211_ATTR_MLO_LINK_ID];
16558 
16559 		if (!wdev) {
16560 			err = -EINVAL;
16561 			goto out_unlock;
16562 		}
16563 
16564 		/* MLO -> require valid link ID */
16565 		if (wdev->valid_links &&
16566 		    (!link_id ||
16567 		     !(wdev->valid_links & BIT(nla_get_u8(link_id))))) {
16568 			err = -EINVAL;
16569 			goto out_unlock;
16570 		}
16571 
16572 		/* non-MLO -> no link ID attribute accepted */
16573 		if (!wdev->valid_links && link_id) {
16574 			err = -EINVAL;
16575 			goto out_unlock;
16576 		}
16577 	}
16578 
16579 	if (internal_flags & NL80211_FLAG_MLO_UNSUPPORTED) {
16580 		if (info->attrs[NL80211_ATTR_MLO_LINK_ID] ||
16581 		    (wdev && wdev->valid_links)) {
16582 			err = -EINVAL;
16583 			goto out_unlock;
16584 		}
16585 	}
16586 
16587 	if (rdev && !(internal_flags & NL80211_FLAG_NO_WIPHY_MTX)) {
16588 		wiphy_lock(&rdev->wiphy);
16589 		/* we keep the mutex locked until post_doit */
16590 		__release(&rdev->wiphy.mtx);
16591 	}
16592 	if (!(internal_flags & NL80211_FLAG_NEED_RTNL))
16593 		rtnl_unlock();
16594 
16595 	return 0;
16596 out_unlock:
16597 	rtnl_unlock();
16598 	dev_put(dev);
16599 	return err;
16600 }
16601 
nl80211_post_doit(const struct genl_split_ops * ops,struct sk_buff * skb,struct genl_info * info)16602 static void nl80211_post_doit(const struct genl_split_ops *ops,
16603 			      struct sk_buff *skb,
16604 			      struct genl_info *info)
16605 {
16606 	u32 internal_flags = nl80211_internal_flags[ops->internal_flags];
16607 
16608 	if (info->user_ptr[1]) {
16609 		if (internal_flags & NL80211_FLAG_NEED_WDEV) {
16610 			struct wireless_dev *wdev = info->user_ptr[1];
16611 
16612 			dev_put(wdev->netdev);
16613 		} else {
16614 			dev_put(info->user_ptr[1]);
16615 		}
16616 	}
16617 
16618 	if (info->user_ptr[0] &&
16619 	    !(internal_flags & NL80211_FLAG_NO_WIPHY_MTX)) {
16620 		struct cfg80211_registered_device *rdev = info->user_ptr[0];
16621 
16622 		/* we kept the mutex locked since pre_doit */
16623 		__acquire(&rdev->wiphy.mtx);
16624 		wiphy_unlock(&rdev->wiphy);
16625 	}
16626 
16627 	if (internal_flags & NL80211_FLAG_NEED_RTNL)
16628 		rtnl_unlock();
16629 
16630 	/* If needed, clear the netlink message payload from the SKB
16631 	 * as it might contain key data that shouldn't stick around on
16632 	 * the heap after the SKB is freed. The netlink message header
16633 	 * is still needed for further processing, so leave it intact.
16634 	 */
16635 	if (internal_flags & NL80211_FLAG_CLEAR_SKB) {
16636 		struct nlmsghdr *nlh = nlmsg_hdr(skb);
16637 
16638 		memset(nlmsg_data(nlh), 0, nlmsg_len(nlh));
16639 	}
16640 }
16641 
nl80211_set_sar_sub_specs(struct cfg80211_registered_device * rdev,struct cfg80211_sar_specs * sar_specs,struct nlattr * spec[],int index)16642 static int nl80211_set_sar_sub_specs(struct cfg80211_registered_device *rdev,
16643 				     struct cfg80211_sar_specs *sar_specs,
16644 				     struct nlattr *spec[], int index)
16645 {
16646 	u32 range_index, i;
16647 
16648 	if (!sar_specs || !spec)
16649 		return -EINVAL;
16650 
16651 	if (!spec[NL80211_SAR_ATTR_SPECS_POWER] ||
16652 	    !spec[NL80211_SAR_ATTR_SPECS_RANGE_INDEX])
16653 		return -EINVAL;
16654 
16655 	range_index = nla_get_u32(spec[NL80211_SAR_ATTR_SPECS_RANGE_INDEX]);
16656 
16657 	/* check if range_index exceeds num_freq_ranges */
16658 	if (range_index >= rdev->wiphy.sar_capa->num_freq_ranges)
16659 		return -EINVAL;
16660 
16661 	/* check if range_index duplicates */
16662 	for (i = 0; i < index; i++) {
16663 		if (sar_specs->sub_specs[i].freq_range_index == range_index)
16664 			return -EINVAL;
16665 	}
16666 
16667 	sar_specs->sub_specs[index].power =
16668 		nla_get_s32(spec[NL80211_SAR_ATTR_SPECS_POWER]);
16669 
16670 	sar_specs->sub_specs[index].freq_range_index = range_index;
16671 
16672 	return 0;
16673 }
16674 
nl80211_set_sar_specs(struct sk_buff * skb,struct genl_info * info)16675 static int nl80211_set_sar_specs(struct sk_buff *skb, struct genl_info *info)
16676 {
16677 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
16678 	struct nlattr *spec[NL80211_SAR_ATTR_SPECS_MAX + 1];
16679 	struct nlattr *tb[NL80211_SAR_ATTR_MAX + 1];
16680 	struct cfg80211_sar_specs *sar_spec;
16681 	enum nl80211_sar_type type;
16682 	struct nlattr *spec_list;
16683 	u32 specs;
16684 	int rem, err;
16685 
16686 	if (!rdev->wiphy.sar_capa || !rdev->ops->set_sar_specs)
16687 		return -EOPNOTSUPP;
16688 
16689 	if (!info->attrs[NL80211_ATTR_SAR_SPEC])
16690 		return -EINVAL;
16691 
16692 	nla_parse_nested(tb, NL80211_SAR_ATTR_MAX,
16693 			 info->attrs[NL80211_ATTR_SAR_SPEC],
16694 			 NULL, NULL);
16695 
16696 	if (!tb[NL80211_SAR_ATTR_TYPE] || !tb[NL80211_SAR_ATTR_SPECS])
16697 		return -EINVAL;
16698 
16699 	type = nla_get_u32(tb[NL80211_SAR_ATTR_TYPE]);
16700 	if (type != rdev->wiphy.sar_capa->type)
16701 		return -EINVAL;
16702 
16703 	specs = 0;
16704 	nla_for_each_nested(spec_list, tb[NL80211_SAR_ATTR_SPECS], rem)
16705 		specs++;
16706 
16707 	if (specs > rdev->wiphy.sar_capa->num_freq_ranges)
16708 		return -EINVAL;
16709 
16710 	sar_spec = kzalloc(struct_size(sar_spec, sub_specs, specs), GFP_KERNEL);
16711 	if (!sar_spec)
16712 		return -ENOMEM;
16713 
16714 	sar_spec->type = type;
16715 	specs = 0;
16716 	nla_for_each_nested(spec_list, tb[NL80211_SAR_ATTR_SPECS], rem) {
16717 		nla_parse_nested(spec, NL80211_SAR_ATTR_SPECS_MAX,
16718 				 spec_list, NULL, NULL);
16719 
16720 		switch (type) {
16721 		case NL80211_SAR_TYPE_POWER:
16722 			if (nl80211_set_sar_sub_specs(rdev, sar_spec,
16723 						      spec, specs)) {
16724 				err = -EINVAL;
16725 				goto error;
16726 			}
16727 			break;
16728 		default:
16729 			err = -EINVAL;
16730 			goto error;
16731 		}
16732 		specs++;
16733 	}
16734 
16735 	sar_spec->num_sub_specs = specs;
16736 
16737 	rdev->cur_cmd_info = info;
16738 	err = rdev_set_sar_specs(rdev, sar_spec);
16739 	rdev->cur_cmd_info = NULL;
16740 error:
16741 	kfree(sar_spec);
16742 	return err;
16743 }
16744 
16745 #define SELECTOR(__sel, name, value) \
16746 	((__sel) == (value)) ? NL80211_IFL_SEL_##name :
16747 int __missing_selector(void);
16748 #define IFLAGS(__val) INTERNAL_FLAG_SELECTORS(__val) __missing_selector()
16749 
16750 static const struct genl_ops nl80211_ops[] = {
16751 	{
16752 		.cmd = NL80211_CMD_GET_WIPHY,
16753 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16754 		.doit = nl80211_get_wiphy,
16755 		.dumpit = nl80211_dump_wiphy,
16756 		.done = nl80211_dump_wiphy_done,
16757 		/* can be retrieved by unprivileged users */
16758 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WIPHY),
16759 	},
16760 };
16761 
16762 static const struct genl_small_ops nl80211_small_ops[] = {
16763 	{
16764 		.cmd = NL80211_CMD_SET_WIPHY,
16765 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16766 		.doit = nl80211_set_wiphy,
16767 		.flags = GENL_UNS_ADMIN_PERM,
16768 	},
16769 	{
16770 		.cmd = NL80211_CMD_GET_INTERFACE,
16771 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16772 		.doit = nl80211_get_interface,
16773 		.dumpit = nl80211_dump_interface,
16774 		/* can be retrieved by unprivileged users */
16775 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV),
16776 	},
16777 	{
16778 		.cmd = NL80211_CMD_SET_INTERFACE,
16779 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16780 		.doit = nl80211_set_interface,
16781 		.flags = GENL_UNS_ADMIN_PERM,
16782 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV |
16783 					 NL80211_FLAG_NEED_RTNL),
16784 	},
16785 	{
16786 		.cmd = NL80211_CMD_NEW_INTERFACE,
16787 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16788 		.doit = nl80211_new_interface,
16789 		.flags = GENL_UNS_ADMIN_PERM,
16790 		.internal_flags =
16791 			IFLAGS(NL80211_FLAG_NEED_WIPHY |
16792 			       NL80211_FLAG_NEED_RTNL |
16793 			       /* we take the wiphy mutex later ourselves */
16794 			       NL80211_FLAG_NO_WIPHY_MTX),
16795 	},
16796 	{
16797 		.cmd = NL80211_CMD_DEL_INTERFACE,
16798 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16799 		.doit = nl80211_del_interface,
16800 		.flags = GENL_UNS_ADMIN_PERM,
16801 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV |
16802 					 NL80211_FLAG_NEED_RTNL),
16803 	},
16804 	{
16805 		.cmd = NL80211_CMD_GET_KEY,
16806 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16807 		.doit = nl80211_get_key,
16808 		.flags = GENL_UNS_ADMIN_PERM,
16809 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
16810 	},
16811 	{
16812 		.cmd = NL80211_CMD_SET_KEY,
16813 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16814 		.doit = nl80211_set_key,
16815 		.flags = GENL_UNS_ADMIN_PERM,
16816 		/* cannot use NL80211_FLAG_MLO_VALID_LINK_ID, depends on key */
16817 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
16818 					 NL80211_FLAG_CLEAR_SKB),
16819 	},
16820 	{
16821 		.cmd = NL80211_CMD_NEW_KEY,
16822 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16823 		.doit = nl80211_new_key,
16824 		.flags = GENL_UNS_ADMIN_PERM,
16825 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
16826 					 NL80211_FLAG_CLEAR_SKB),
16827 	},
16828 	{
16829 		.cmd = NL80211_CMD_DEL_KEY,
16830 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16831 		.doit = nl80211_del_key,
16832 		.flags = GENL_UNS_ADMIN_PERM,
16833 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
16834 	},
16835 	{
16836 		.cmd = NL80211_CMD_SET_BEACON,
16837 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16838 		.flags = GENL_UNS_ADMIN_PERM,
16839 		.doit = nl80211_set_beacon,
16840 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
16841 					 NL80211_FLAG_MLO_VALID_LINK_ID),
16842 	},
16843 	{
16844 		.cmd = NL80211_CMD_START_AP,
16845 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16846 		.flags = GENL_UNS_ADMIN_PERM,
16847 		.doit = nl80211_start_ap,
16848 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
16849 					 NL80211_FLAG_MLO_VALID_LINK_ID),
16850 	},
16851 	{
16852 		.cmd = NL80211_CMD_STOP_AP,
16853 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16854 		.flags = GENL_UNS_ADMIN_PERM,
16855 		.doit = nl80211_stop_ap,
16856 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
16857 					 NL80211_FLAG_MLO_VALID_LINK_ID),
16858 	},
16859 	{
16860 		.cmd = NL80211_CMD_GET_STATION,
16861 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16862 		.doit = nl80211_get_station,
16863 		.dumpit = nl80211_dump_station,
16864 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV),
16865 	},
16866 	{
16867 		.cmd = NL80211_CMD_SET_STATION,
16868 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16869 		.doit = nl80211_set_station,
16870 		.flags = GENL_UNS_ADMIN_PERM,
16871 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
16872 	},
16873 	{
16874 		.cmd = NL80211_CMD_NEW_STATION,
16875 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16876 		.doit = nl80211_new_station,
16877 		.flags = GENL_UNS_ADMIN_PERM,
16878 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
16879 	},
16880 	{
16881 		.cmd = NL80211_CMD_DEL_STATION,
16882 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16883 		.doit = nl80211_del_station,
16884 		.flags = GENL_UNS_ADMIN_PERM,
16885 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
16886 	},
16887 	{
16888 		.cmd = NL80211_CMD_GET_MPATH,
16889 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16890 		.doit = nl80211_get_mpath,
16891 		.dumpit = nl80211_dump_mpath,
16892 		.flags = GENL_UNS_ADMIN_PERM,
16893 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
16894 	},
16895 	{
16896 		.cmd = NL80211_CMD_GET_MPP,
16897 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16898 		.doit = nl80211_get_mpp,
16899 		.dumpit = nl80211_dump_mpp,
16900 		.flags = GENL_UNS_ADMIN_PERM,
16901 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
16902 	},
16903 	{
16904 		.cmd = NL80211_CMD_SET_MPATH,
16905 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16906 		.doit = nl80211_set_mpath,
16907 		.flags = GENL_UNS_ADMIN_PERM,
16908 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
16909 	},
16910 	{
16911 		.cmd = NL80211_CMD_NEW_MPATH,
16912 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16913 		.doit = nl80211_new_mpath,
16914 		.flags = GENL_UNS_ADMIN_PERM,
16915 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
16916 	},
16917 	{
16918 		.cmd = NL80211_CMD_DEL_MPATH,
16919 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16920 		.doit = nl80211_del_mpath,
16921 		.flags = GENL_UNS_ADMIN_PERM,
16922 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
16923 	},
16924 	{
16925 		.cmd = NL80211_CMD_SET_BSS,
16926 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16927 		.doit = nl80211_set_bss,
16928 		.flags = GENL_UNS_ADMIN_PERM,
16929 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
16930 					 NL80211_FLAG_MLO_VALID_LINK_ID),
16931 	},
16932 	{
16933 		.cmd = NL80211_CMD_GET_REG,
16934 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16935 		.doit = nl80211_get_reg_do,
16936 		.dumpit = nl80211_get_reg_dump,
16937 		/* can be retrieved by unprivileged users */
16938 	},
16939 #ifdef CONFIG_CFG80211_CRDA_SUPPORT
16940 	{
16941 		.cmd = NL80211_CMD_SET_REG,
16942 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16943 		.doit = nl80211_set_reg,
16944 		.flags = GENL_ADMIN_PERM,
16945 	},
16946 #endif
16947 	{
16948 		.cmd = NL80211_CMD_REQ_SET_REG,
16949 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16950 		.doit = nl80211_req_set_reg,
16951 		.flags = GENL_ADMIN_PERM,
16952 	},
16953 	{
16954 		.cmd = NL80211_CMD_RELOAD_REGDB,
16955 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16956 		.doit = nl80211_reload_regdb,
16957 		.flags = GENL_ADMIN_PERM,
16958 	},
16959 	{
16960 		.cmd = NL80211_CMD_GET_MESH_CONFIG,
16961 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16962 		.doit = nl80211_get_mesh_config,
16963 		/* can be retrieved by unprivileged users */
16964 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
16965 	},
16966 	{
16967 		.cmd = NL80211_CMD_SET_MESH_CONFIG,
16968 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16969 		.doit = nl80211_update_mesh_config,
16970 		.flags = GENL_UNS_ADMIN_PERM,
16971 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
16972 	},
16973 	{
16974 		.cmd = NL80211_CMD_TRIGGER_SCAN,
16975 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16976 		.doit = nl80211_trigger_scan,
16977 		.flags = GENL_UNS_ADMIN_PERM,
16978 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP),
16979 	},
16980 	{
16981 		.cmd = NL80211_CMD_ABORT_SCAN,
16982 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16983 		.doit = nl80211_abort_scan,
16984 		.flags = GENL_UNS_ADMIN_PERM,
16985 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP),
16986 	},
16987 	{
16988 		.cmd = NL80211_CMD_GET_SCAN,
16989 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16990 		.dumpit = nl80211_dump_scan,
16991 	},
16992 	{
16993 		.cmd = NL80211_CMD_START_SCHED_SCAN,
16994 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16995 		.doit = nl80211_start_sched_scan,
16996 		.flags = GENL_UNS_ADMIN_PERM,
16997 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
16998 	},
16999 	{
17000 		.cmd = NL80211_CMD_STOP_SCHED_SCAN,
17001 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17002 		.doit = nl80211_stop_sched_scan,
17003 		.flags = GENL_UNS_ADMIN_PERM,
17004 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17005 	},
17006 	{
17007 		.cmd = NL80211_CMD_AUTHENTICATE,
17008 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17009 		.doit = nl80211_authenticate,
17010 		.flags = GENL_UNS_ADMIN_PERM,
17011 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17012 					 NL80211_FLAG_CLEAR_SKB),
17013 	},
17014 	{
17015 		.cmd = NL80211_CMD_ASSOCIATE,
17016 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17017 		.doit = nl80211_associate,
17018 		.flags = GENL_UNS_ADMIN_PERM,
17019 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17020 					 NL80211_FLAG_CLEAR_SKB),
17021 	},
17022 	{
17023 		.cmd = NL80211_CMD_DEAUTHENTICATE,
17024 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17025 		.doit = nl80211_deauthenticate,
17026 		.flags = GENL_UNS_ADMIN_PERM,
17027 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17028 	},
17029 	{
17030 		.cmd = NL80211_CMD_DISASSOCIATE,
17031 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17032 		.doit = nl80211_disassociate,
17033 		.flags = GENL_UNS_ADMIN_PERM,
17034 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17035 	},
17036 	{
17037 		.cmd = NL80211_CMD_JOIN_IBSS,
17038 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17039 		.doit = nl80211_join_ibss,
17040 		.flags = GENL_UNS_ADMIN_PERM,
17041 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17042 	},
17043 	{
17044 		.cmd = NL80211_CMD_LEAVE_IBSS,
17045 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17046 		.doit = nl80211_leave_ibss,
17047 		.flags = GENL_UNS_ADMIN_PERM,
17048 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17049 	},
17050 #ifdef CONFIG_NL80211_TESTMODE
17051 	{
17052 		.cmd = NL80211_CMD_TESTMODE,
17053 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17054 		.doit = nl80211_testmode_do,
17055 		.dumpit = nl80211_testmode_dump,
17056 		.flags = GENL_UNS_ADMIN_PERM,
17057 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WIPHY),
17058 	},
17059 #endif
17060 	{
17061 		.cmd = NL80211_CMD_CONNECT,
17062 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17063 		.doit = nl80211_connect,
17064 		.flags = GENL_UNS_ADMIN_PERM,
17065 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17066 					 NL80211_FLAG_CLEAR_SKB),
17067 	},
17068 	{
17069 		.cmd = NL80211_CMD_UPDATE_CONNECT_PARAMS,
17070 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17071 		.doit = nl80211_update_connect_params,
17072 		.flags = GENL_ADMIN_PERM,
17073 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17074 					 NL80211_FLAG_CLEAR_SKB),
17075 	},
17076 	{
17077 		.cmd = NL80211_CMD_DISCONNECT,
17078 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17079 		.doit = nl80211_disconnect,
17080 		.flags = GENL_UNS_ADMIN_PERM,
17081 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17082 	},
17083 	{
17084 		.cmd = NL80211_CMD_SET_WIPHY_NETNS,
17085 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17086 		.doit = nl80211_wiphy_netns,
17087 		.flags = GENL_UNS_ADMIN_PERM,
17088 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WIPHY |
17089 					 NL80211_FLAG_NEED_RTNL |
17090 					 NL80211_FLAG_NO_WIPHY_MTX),
17091 	},
17092 	{
17093 		.cmd = NL80211_CMD_GET_SURVEY,
17094 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17095 		.dumpit = nl80211_dump_survey,
17096 	},
17097 	{
17098 		.cmd = NL80211_CMD_SET_PMKSA,
17099 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17100 		.doit = nl80211_setdel_pmksa,
17101 		.flags = GENL_UNS_ADMIN_PERM,
17102 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17103 					 NL80211_FLAG_CLEAR_SKB),
17104 	},
17105 	{
17106 		.cmd = NL80211_CMD_DEL_PMKSA,
17107 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17108 		.doit = nl80211_setdel_pmksa,
17109 		.flags = GENL_UNS_ADMIN_PERM,
17110 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17111 	},
17112 	{
17113 		.cmd = NL80211_CMD_FLUSH_PMKSA,
17114 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17115 		.doit = nl80211_flush_pmksa,
17116 		.flags = GENL_UNS_ADMIN_PERM,
17117 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17118 	},
17119 	{
17120 		.cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
17121 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17122 		.doit = nl80211_remain_on_channel,
17123 		.flags = GENL_UNS_ADMIN_PERM,
17124 		/* FIXME: requiring a link ID here is probably not good */
17125 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP |
17126 					 NL80211_FLAG_MLO_VALID_LINK_ID),
17127 	},
17128 	{
17129 		.cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
17130 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17131 		.doit = nl80211_cancel_remain_on_channel,
17132 		.flags = GENL_UNS_ADMIN_PERM,
17133 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP),
17134 	},
17135 	{
17136 		.cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
17137 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17138 		.doit = nl80211_set_tx_bitrate_mask,
17139 		.flags = GENL_UNS_ADMIN_PERM,
17140 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV |
17141 					 NL80211_FLAG_MLO_VALID_LINK_ID),
17142 	},
17143 	{
17144 		.cmd = NL80211_CMD_REGISTER_FRAME,
17145 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17146 		.doit = nl80211_register_mgmt,
17147 		.flags = GENL_UNS_ADMIN_PERM,
17148 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV),
17149 	},
17150 	{
17151 		.cmd = NL80211_CMD_FRAME,
17152 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17153 		.doit = nl80211_tx_mgmt,
17154 		.flags = GENL_UNS_ADMIN_PERM,
17155 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP),
17156 	},
17157 	{
17158 		.cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
17159 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17160 		.doit = nl80211_tx_mgmt_cancel_wait,
17161 		.flags = GENL_UNS_ADMIN_PERM,
17162 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP),
17163 	},
17164 	{
17165 		.cmd = NL80211_CMD_SET_POWER_SAVE,
17166 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17167 		.doit = nl80211_set_power_save,
17168 		.flags = GENL_UNS_ADMIN_PERM,
17169 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV),
17170 	},
17171 	{
17172 		.cmd = NL80211_CMD_GET_POWER_SAVE,
17173 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17174 		.doit = nl80211_get_power_save,
17175 		/* can be retrieved by unprivileged users */
17176 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV),
17177 	},
17178 	{
17179 		.cmd = NL80211_CMD_SET_CQM,
17180 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17181 		.doit = nl80211_set_cqm,
17182 		.flags = GENL_UNS_ADMIN_PERM,
17183 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV),
17184 	},
17185 	{
17186 		.cmd = NL80211_CMD_SET_CHANNEL,
17187 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17188 		.doit = nl80211_set_channel,
17189 		.flags = GENL_UNS_ADMIN_PERM,
17190 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV |
17191 					 NL80211_FLAG_MLO_VALID_LINK_ID),
17192 	},
17193 	{
17194 		.cmd = NL80211_CMD_JOIN_MESH,
17195 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17196 		.doit = nl80211_join_mesh,
17197 		.flags = GENL_UNS_ADMIN_PERM,
17198 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17199 	},
17200 	{
17201 		.cmd = NL80211_CMD_LEAVE_MESH,
17202 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17203 		.doit = nl80211_leave_mesh,
17204 		.flags = GENL_UNS_ADMIN_PERM,
17205 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17206 	},
17207 	{
17208 		.cmd = NL80211_CMD_JOIN_OCB,
17209 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17210 		.doit = nl80211_join_ocb,
17211 		.flags = GENL_UNS_ADMIN_PERM,
17212 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17213 	},
17214 	{
17215 		.cmd = NL80211_CMD_LEAVE_OCB,
17216 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17217 		.doit = nl80211_leave_ocb,
17218 		.flags = GENL_UNS_ADMIN_PERM,
17219 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17220 	},
17221 #ifdef CONFIG_PM
17222 	{
17223 		.cmd = NL80211_CMD_GET_WOWLAN,
17224 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17225 		.doit = nl80211_get_wowlan,
17226 		/* can be retrieved by unprivileged users */
17227 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WIPHY),
17228 	},
17229 	{
17230 		.cmd = NL80211_CMD_SET_WOWLAN,
17231 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17232 		.doit = nl80211_set_wowlan,
17233 		.flags = GENL_UNS_ADMIN_PERM,
17234 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WIPHY),
17235 	},
17236 #endif
17237 	{
17238 		.cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
17239 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17240 		.doit = nl80211_set_rekey_data,
17241 		.flags = GENL_UNS_ADMIN_PERM,
17242 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17243 					 NL80211_FLAG_CLEAR_SKB),
17244 	},
17245 	{
17246 		.cmd = NL80211_CMD_TDLS_MGMT,
17247 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17248 		.doit = nl80211_tdls_mgmt,
17249 		.flags = GENL_UNS_ADMIN_PERM,
17250 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17251 					 NL80211_FLAG_MLO_VALID_LINK_ID),
17252 	},
17253 	{
17254 		.cmd = NL80211_CMD_TDLS_OPER,
17255 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17256 		.doit = nl80211_tdls_oper,
17257 		.flags = GENL_UNS_ADMIN_PERM,
17258 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17259 	},
17260 	{
17261 		.cmd = NL80211_CMD_UNEXPECTED_FRAME,
17262 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17263 		.doit = nl80211_register_unexpected_frame,
17264 		.flags = GENL_UNS_ADMIN_PERM,
17265 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV),
17266 	},
17267 	{
17268 		.cmd = NL80211_CMD_PROBE_CLIENT,
17269 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17270 		.doit = nl80211_probe_client,
17271 		.flags = GENL_UNS_ADMIN_PERM,
17272 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17273 	},
17274 	{
17275 		.cmd = NL80211_CMD_REGISTER_BEACONS,
17276 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17277 		.doit = nl80211_register_beacons,
17278 		.flags = GENL_UNS_ADMIN_PERM,
17279 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WIPHY),
17280 	},
17281 	{
17282 		.cmd = NL80211_CMD_SET_NOACK_MAP,
17283 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17284 		.doit = nl80211_set_noack_map,
17285 		.flags = GENL_UNS_ADMIN_PERM,
17286 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV),
17287 	},
17288 	{
17289 		.cmd = NL80211_CMD_START_P2P_DEVICE,
17290 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17291 		.doit = nl80211_start_p2p_device,
17292 		.flags = GENL_UNS_ADMIN_PERM,
17293 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV |
17294 					 NL80211_FLAG_NEED_RTNL),
17295 	},
17296 	{
17297 		.cmd = NL80211_CMD_STOP_P2P_DEVICE,
17298 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17299 		.doit = nl80211_stop_p2p_device,
17300 		.flags = GENL_UNS_ADMIN_PERM,
17301 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP |
17302 					 NL80211_FLAG_NEED_RTNL),
17303 	},
17304 	{
17305 		.cmd = NL80211_CMD_START_NAN,
17306 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17307 		.doit = nl80211_start_nan,
17308 		.flags = GENL_ADMIN_PERM,
17309 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV |
17310 					 NL80211_FLAG_NEED_RTNL),
17311 	},
17312 	{
17313 		.cmd = NL80211_CMD_STOP_NAN,
17314 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17315 		.doit = nl80211_stop_nan,
17316 		.flags = GENL_ADMIN_PERM,
17317 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP |
17318 					 NL80211_FLAG_NEED_RTNL),
17319 	},
17320 	{
17321 		.cmd = NL80211_CMD_ADD_NAN_FUNCTION,
17322 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17323 		.doit = nl80211_nan_add_func,
17324 		.flags = GENL_ADMIN_PERM,
17325 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP),
17326 	},
17327 	{
17328 		.cmd = NL80211_CMD_DEL_NAN_FUNCTION,
17329 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17330 		.doit = nl80211_nan_del_func,
17331 		.flags = GENL_ADMIN_PERM,
17332 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP),
17333 	},
17334 	{
17335 		.cmd = NL80211_CMD_CHANGE_NAN_CONFIG,
17336 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17337 		.doit = nl80211_nan_change_config,
17338 		.flags = GENL_ADMIN_PERM,
17339 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP),
17340 	},
17341 	{
17342 		.cmd = NL80211_CMD_SET_MCAST_RATE,
17343 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17344 		.doit = nl80211_set_mcast_rate,
17345 		.flags = GENL_UNS_ADMIN_PERM,
17346 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV),
17347 	},
17348 	{
17349 		.cmd = NL80211_CMD_SET_MAC_ACL,
17350 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17351 		.doit = nl80211_set_mac_acl,
17352 		.flags = GENL_UNS_ADMIN_PERM,
17353 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV |
17354 					 NL80211_FLAG_MLO_UNSUPPORTED),
17355 	},
17356 	{
17357 		.cmd = NL80211_CMD_RADAR_DETECT,
17358 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17359 		.doit = nl80211_start_radar_detection,
17360 		.flags = GENL_UNS_ADMIN_PERM,
17361 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17362 					 NL80211_FLAG_NO_WIPHY_MTX |
17363 					 NL80211_FLAG_MLO_UNSUPPORTED),
17364 	},
17365 	{
17366 		.cmd = NL80211_CMD_GET_PROTOCOL_FEATURES,
17367 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17368 		.doit = nl80211_get_protocol_features,
17369 	},
17370 	{
17371 		.cmd = NL80211_CMD_UPDATE_FT_IES,
17372 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17373 		.doit = nl80211_update_ft_ies,
17374 		.flags = GENL_UNS_ADMIN_PERM,
17375 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17376 	},
17377 	{
17378 		.cmd = NL80211_CMD_CRIT_PROTOCOL_START,
17379 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17380 		.doit = nl80211_crit_protocol_start,
17381 		.flags = GENL_UNS_ADMIN_PERM,
17382 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP),
17383 	},
17384 	{
17385 		.cmd = NL80211_CMD_CRIT_PROTOCOL_STOP,
17386 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17387 		.doit = nl80211_crit_protocol_stop,
17388 		.flags = GENL_UNS_ADMIN_PERM,
17389 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP),
17390 	},
17391 	{
17392 		.cmd = NL80211_CMD_GET_COALESCE,
17393 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17394 		.doit = nl80211_get_coalesce,
17395 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WIPHY),
17396 	},
17397 	{
17398 		.cmd = NL80211_CMD_SET_COALESCE,
17399 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17400 		.doit = nl80211_set_coalesce,
17401 		.flags = GENL_UNS_ADMIN_PERM,
17402 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WIPHY),
17403 	},
17404 	{
17405 		.cmd = NL80211_CMD_CHANNEL_SWITCH,
17406 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17407 		.doit = nl80211_channel_switch,
17408 		.flags = GENL_UNS_ADMIN_PERM,
17409 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17410 					 NL80211_FLAG_MLO_VALID_LINK_ID),
17411 	},
17412 	{
17413 		.cmd = NL80211_CMD_VENDOR,
17414 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17415 		.doit = nl80211_vendor_cmd,
17416 		.dumpit = nl80211_vendor_cmd_dump,
17417 		.flags = GENL_UNS_ADMIN_PERM,
17418 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WIPHY |
17419 					 NL80211_FLAG_CLEAR_SKB),
17420 	},
17421 	{
17422 		.cmd = NL80211_CMD_SET_QOS_MAP,
17423 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17424 		.doit = nl80211_set_qos_map,
17425 		.flags = GENL_UNS_ADMIN_PERM,
17426 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17427 	},
17428 	{
17429 		.cmd = NL80211_CMD_ADD_TX_TS,
17430 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17431 		.doit = nl80211_add_tx_ts,
17432 		.flags = GENL_UNS_ADMIN_PERM,
17433 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17434 					 NL80211_FLAG_MLO_UNSUPPORTED),
17435 	},
17436 	{
17437 		.cmd = NL80211_CMD_DEL_TX_TS,
17438 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17439 		.doit = nl80211_del_tx_ts,
17440 		.flags = GENL_UNS_ADMIN_PERM,
17441 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17442 	},
17443 	{
17444 		.cmd = NL80211_CMD_TDLS_CHANNEL_SWITCH,
17445 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17446 		.doit = nl80211_tdls_channel_switch,
17447 		.flags = GENL_UNS_ADMIN_PERM,
17448 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17449 	},
17450 	{
17451 		.cmd = NL80211_CMD_TDLS_CANCEL_CHANNEL_SWITCH,
17452 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17453 		.doit = nl80211_tdls_cancel_channel_switch,
17454 		.flags = GENL_UNS_ADMIN_PERM,
17455 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17456 	},
17457 	{
17458 		.cmd = NL80211_CMD_SET_MULTICAST_TO_UNICAST,
17459 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17460 		.doit = nl80211_set_multicast_to_unicast,
17461 		.flags = GENL_UNS_ADMIN_PERM,
17462 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV),
17463 	},
17464 	{
17465 		.cmd = NL80211_CMD_SET_PMK,
17466 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17467 		.doit = nl80211_set_pmk,
17468 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17469 					 NL80211_FLAG_CLEAR_SKB),
17470 	},
17471 	{
17472 		.cmd = NL80211_CMD_DEL_PMK,
17473 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17474 		.doit = nl80211_del_pmk,
17475 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17476 	},
17477 	{
17478 		.cmd = NL80211_CMD_EXTERNAL_AUTH,
17479 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17480 		.doit = nl80211_external_auth,
17481 		.flags = GENL_ADMIN_PERM,
17482 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17483 	},
17484 	{
17485 		.cmd = NL80211_CMD_CONTROL_PORT_FRAME,
17486 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17487 		.doit = nl80211_tx_control_port,
17488 		.flags = GENL_UNS_ADMIN_PERM,
17489 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17490 	},
17491 	{
17492 		.cmd = NL80211_CMD_GET_FTM_RESPONDER_STATS,
17493 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17494 		.doit = nl80211_get_ftm_responder_stats,
17495 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV |
17496 					 NL80211_FLAG_MLO_VALID_LINK_ID),
17497 	},
17498 	{
17499 		.cmd = NL80211_CMD_PEER_MEASUREMENT_START,
17500 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17501 		.doit = nl80211_pmsr_start,
17502 		.flags = GENL_UNS_ADMIN_PERM,
17503 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP),
17504 	},
17505 	{
17506 		.cmd = NL80211_CMD_NOTIFY_RADAR,
17507 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17508 		.doit = nl80211_notify_radar_detection,
17509 		.flags = GENL_UNS_ADMIN_PERM,
17510 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17511 	},
17512 	{
17513 		.cmd = NL80211_CMD_UPDATE_OWE_INFO,
17514 		.doit = nl80211_update_owe_info,
17515 		.flags = GENL_ADMIN_PERM,
17516 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17517 	},
17518 	{
17519 		.cmd = NL80211_CMD_PROBE_MESH_LINK,
17520 		.doit = nl80211_probe_mesh_link,
17521 		.flags = GENL_UNS_ADMIN_PERM,
17522 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17523 	},
17524 	{
17525 		.cmd = NL80211_CMD_SET_TID_CONFIG,
17526 		.doit = nl80211_set_tid_config,
17527 		.flags = GENL_UNS_ADMIN_PERM,
17528 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV |
17529 					 NL80211_FLAG_MLO_VALID_LINK_ID),
17530 	},
17531 	{
17532 		.cmd = NL80211_CMD_SET_SAR_SPECS,
17533 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17534 		.doit = nl80211_set_sar_specs,
17535 		.flags = GENL_UNS_ADMIN_PERM,
17536 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_WIPHY |
17537 					 NL80211_FLAG_NEED_RTNL),
17538 	},
17539 	{
17540 		.cmd = NL80211_CMD_COLOR_CHANGE_REQUEST,
17541 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17542 		.doit = nl80211_color_change,
17543 		.flags = GENL_UNS_ADMIN_PERM,
17544 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17545 	},
17546 	{
17547 		.cmd = NL80211_CMD_SET_FILS_AAD,
17548 		.validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
17549 		.doit = nl80211_set_fils_aad,
17550 		.flags = GENL_UNS_ADMIN_PERM,
17551 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17552 	},
17553 	{
17554 		.cmd = NL80211_CMD_ADD_LINK,
17555 		.doit = nl80211_add_link,
17556 		.flags = GENL_UNS_ADMIN_PERM,
17557 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17558 	},
17559 	{
17560 		.cmd = NL80211_CMD_REMOVE_LINK,
17561 		.doit = nl80211_remove_link,
17562 		.flags = GENL_UNS_ADMIN_PERM,
17563 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17564 					 NL80211_FLAG_MLO_VALID_LINK_ID),
17565 	},
17566 	{
17567 		.cmd = NL80211_CMD_ADD_LINK_STA,
17568 		.doit = nl80211_add_link_station,
17569 		.flags = GENL_UNS_ADMIN_PERM,
17570 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17571 					 NL80211_FLAG_MLO_VALID_LINK_ID),
17572 	},
17573 	{
17574 		.cmd = NL80211_CMD_MODIFY_LINK_STA,
17575 		.doit = nl80211_modify_link_station,
17576 		.flags = GENL_UNS_ADMIN_PERM,
17577 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17578 					 NL80211_FLAG_MLO_VALID_LINK_ID),
17579 	},
17580 	{
17581 		.cmd = NL80211_CMD_REMOVE_LINK_STA,
17582 		.doit = nl80211_remove_link_station,
17583 		.flags = GENL_UNS_ADMIN_PERM,
17584 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP |
17585 					 NL80211_FLAG_MLO_VALID_LINK_ID),
17586 	},
17587 	{
17588 		.cmd = NL80211_CMD_SET_HW_TIMESTAMP,
17589 		.doit = nl80211_set_hw_timestamp,
17590 		.flags = GENL_UNS_ADMIN_PERM,
17591 		.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
17592 	},
17593 };
17594 
17595 static struct genl_family nl80211_fam __ro_after_init = {
17596 	.name = NL80211_GENL_NAME,	/* have users key off the name instead */
17597 	.hdrsize = 0,			/* no private header */
17598 	.version = 1,			/* no particular meaning now */
17599 	.maxattr = NL80211_ATTR_MAX,
17600 	.policy = nl80211_policy,
17601 	.netnsok = true,
17602 	.pre_doit = nl80211_pre_doit,
17603 	.post_doit = nl80211_post_doit,
17604 	.module = THIS_MODULE,
17605 	.ops = nl80211_ops,
17606 	.n_ops = ARRAY_SIZE(nl80211_ops),
17607 	.small_ops = nl80211_small_ops,
17608 	.n_small_ops = ARRAY_SIZE(nl80211_small_ops),
17609 	.resv_start_op = NL80211_CMD_REMOVE_LINK_STA + 1,
17610 	.mcgrps = nl80211_mcgrps,
17611 	.n_mcgrps = ARRAY_SIZE(nl80211_mcgrps),
17612 	.parallel_ops = true,
17613 };
17614 
17615 /* notification functions */
17616 
nl80211_notify_wiphy(struct cfg80211_registered_device * rdev,enum nl80211_commands cmd)17617 void nl80211_notify_wiphy(struct cfg80211_registered_device *rdev,
17618 			  enum nl80211_commands cmd)
17619 {
17620 	struct sk_buff *msg;
17621 	struct nl80211_dump_wiphy_state state = {};
17622 
17623 	WARN_ON(cmd != NL80211_CMD_NEW_WIPHY &&
17624 		cmd != NL80211_CMD_DEL_WIPHY);
17625 
17626 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
17627 	if (!msg)
17628 		return;
17629 
17630 	if (nl80211_send_wiphy(rdev, cmd, msg, 0, 0, 0, &state) < 0) {
17631 		nlmsg_free(msg);
17632 		return;
17633 	}
17634 
17635 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
17636 				NL80211_MCGRP_CONFIG, GFP_KERNEL);
17637 }
17638 
nl80211_notify_iface(struct cfg80211_registered_device * rdev,struct wireless_dev * wdev,enum nl80211_commands cmd)17639 void nl80211_notify_iface(struct cfg80211_registered_device *rdev,
17640 				struct wireless_dev *wdev,
17641 				enum nl80211_commands cmd)
17642 {
17643 	struct sk_buff *msg;
17644 
17645 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
17646 	if (!msg)
17647 		return;
17648 
17649 	if (nl80211_send_iface(msg, 0, 0, 0, rdev, wdev, cmd) < 0) {
17650 		nlmsg_free(msg);
17651 		return;
17652 	}
17653 
17654 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
17655 				NL80211_MCGRP_CONFIG, GFP_KERNEL);
17656 }
17657 
nl80211_add_scan_req(struct sk_buff * msg,struct cfg80211_registered_device * rdev)17658 static int nl80211_add_scan_req(struct sk_buff *msg,
17659 				struct cfg80211_registered_device *rdev)
17660 {
17661 	struct cfg80211_scan_request *req = rdev->scan_req;
17662 	struct nlattr *nest;
17663 	int i;
17664 	struct cfg80211_scan_info *info;
17665 
17666 	if (WARN_ON(!req))
17667 		return 0;
17668 
17669 	nest = nla_nest_start_noflag(msg, NL80211_ATTR_SCAN_SSIDS);
17670 	if (!nest)
17671 		goto nla_put_failure;
17672 	for (i = 0; i < req->n_ssids; i++) {
17673 		if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
17674 			goto nla_put_failure;
17675 	}
17676 	nla_nest_end(msg, nest);
17677 
17678 	if (req->flags & NL80211_SCAN_FLAG_FREQ_KHZ) {
17679 		nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQ_KHZ);
17680 		if (!nest)
17681 			goto nla_put_failure;
17682 		for (i = 0; i < req->n_channels; i++) {
17683 			if (nla_put_u32(msg, i,
17684 				   ieee80211_channel_to_khz(req->channels[i])))
17685 				goto nla_put_failure;
17686 		}
17687 		nla_nest_end(msg, nest);
17688 	} else {
17689 		nest = nla_nest_start_noflag(msg,
17690 					     NL80211_ATTR_SCAN_FREQUENCIES);
17691 		if (!nest)
17692 			goto nla_put_failure;
17693 		for (i = 0; i < req->n_channels; i++) {
17694 			if (nla_put_u32(msg, i, req->channels[i]->center_freq))
17695 				goto nla_put_failure;
17696 		}
17697 		nla_nest_end(msg, nest);
17698 	}
17699 
17700 	if (req->ie &&
17701 	    nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
17702 		goto nla_put_failure;
17703 
17704 	if (req->flags &&
17705 	    nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags))
17706 		goto nla_put_failure;
17707 
17708 	info = rdev->int_scan_req ? &rdev->int_scan_req->info :
17709 		&rdev->scan_req->info;
17710 	if (info->scan_start_tsf &&
17711 	    (nla_put_u64_64bit(msg, NL80211_ATTR_SCAN_START_TIME_TSF,
17712 			       info->scan_start_tsf, NL80211_BSS_PAD) ||
17713 	     nla_put(msg, NL80211_ATTR_SCAN_START_TIME_TSF_BSSID, ETH_ALEN,
17714 		     info->tsf_bssid)))
17715 		goto nla_put_failure;
17716 
17717 	return 0;
17718  nla_put_failure:
17719 	return -ENOBUFS;
17720 }
17721 
nl80211_prep_scan_msg(struct sk_buff * msg,struct cfg80211_registered_device * rdev,struct wireless_dev * wdev,u32 portid,u32 seq,int flags,u32 cmd)17722 static int nl80211_prep_scan_msg(struct sk_buff *msg,
17723 				 struct cfg80211_registered_device *rdev,
17724 				 struct wireless_dev *wdev,
17725 				 u32 portid, u32 seq, int flags,
17726 				 u32 cmd)
17727 {
17728 	void *hdr;
17729 
17730 	hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
17731 	if (!hdr)
17732 		return -1;
17733 
17734 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
17735 	    (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
17736 					 wdev->netdev->ifindex)) ||
17737 	    nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
17738 			      NL80211_ATTR_PAD))
17739 		goto nla_put_failure;
17740 
17741 	/* ignore errors and send incomplete event anyway */
17742 	nl80211_add_scan_req(msg, rdev);
17743 
17744 	genlmsg_end(msg, hdr);
17745 	return 0;
17746 
17747  nla_put_failure:
17748 	genlmsg_cancel(msg, hdr);
17749 	return -EMSGSIZE;
17750 }
17751 
17752 static int
nl80211_prep_sched_scan_msg(struct sk_buff * msg,struct cfg80211_sched_scan_request * req,u32 cmd)17753 nl80211_prep_sched_scan_msg(struct sk_buff *msg,
17754 			    struct cfg80211_sched_scan_request *req, u32 cmd)
17755 {
17756 	void *hdr;
17757 
17758 	hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
17759 	if (!hdr)
17760 		return -1;
17761 
17762 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY,
17763 			wiphy_to_rdev(req->wiphy)->wiphy_idx) ||
17764 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, req->dev->ifindex) ||
17765 	    nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, req->reqid,
17766 			      NL80211_ATTR_PAD))
17767 		goto nla_put_failure;
17768 
17769 	genlmsg_end(msg, hdr);
17770 	return 0;
17771 
17772  nla_put_failure:
17773 	genlmsg_cancel(msg, hdr);
17774 	return -EMSGSIZE;
17775 }
17776 
nl80211_send_scan_start(struct cfg80211_registered_device * rdev,struct wireless_dev * wdev)17777 void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
17778 			     struct wireless_dev *wdev)
17779 {
17780 	struct sk_buff *msg;
17781 
17782 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
17783 	if (!msg)
17784 		return;
17785 
17786 	if (nl80211_prep_scan_msg(msg, rdev, wdev, 0, 0, 0,
17787 				  NL80211_CMD_TRIGGER_SCAN) < 0) {
17788 		nlmsg_free(msg);
17789 		return;
17790 	}
17791 
17792 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
17793 				NL80211_MCGRP_SCAN, GFP_KERNEL);
17794 }
17795 
nl80211_build_scan_msg(struct cfg80211_registered_device * rdev,struct wireless_dev * wdev,bool aborted)17796 struct sk_buff *nl80211_build_scan_msg(struct cfg80211_registered_device *rdev,
17797 				       struct wireless_dev *wdev, bool aborted)
17798 {
17799 	struct sk_buff *msg;
17800 
17801 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
17802 	if (!msg)
17803 		return NULL;
17804 
17805 	if (nl80211_prep_scan_msg(msg, rdev, wdev, 0, 0, 0,
17806 				  aborted ? NL80211_CMD_SCAN_ABORTED :
17807 					    NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
17808 		nlmsg_free(msg);
17809 		return NULL;
17810 	}
17811 
17812 	return msg;
17813 }
17814 
17815 /* send message created by nl80211_build_scan_msg() */
nl80211_send_scan_msg(struct cfg80211_registered_device * rdev,struct sk_buff * msg)17816 void nl80211_send_scan_msg(struct cfg80211_registered_device *rdev,
17817 			   struct sk_buff *msg)
17818 {
17819 	if (!msg)
17820 		return;
17821 
17822 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
17823 				NL80211_MCGRP_SCAN, GFP_KERNEL);
17824 }
17825 
nl80211_send_sched_scan(struct cfg80211_sched_scan_request * req,u32 cmd)17826 void nl80211_send_sched_scan(struct cfg80211_sched_scan_request *req, u32 cmd)
17827 {
17828 	struct sk_buff *msg;
17829 
17830 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
17831 	if (!msg)
17832 		return;
17833 
17834 	if (nl80211_prep_sched_scan_msg(msg, req, cmd) < 0) {
17835 		nlmsg_free(msg);
17836 		return;
17837 	}
17838 
17839 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(req->wiphy), msg, 0,
17840 				NL80211_MCGRP_SCAN, GFP_KERNEL);
17841 }
17842 
nl80211_reg_change_event_fill(struct sk_buff * msg,struct regulatory_request * request)17843 static bool nl80211_reg_change_event_fill(struct sk_buff *msg,
17844 					  struct regulatory_request *request)
17845 {
17846 	/* Userspace can always count this one always being set */
17847 	if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
17848 		goto nla_put_failure;
17849 
17850 	if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
17851 		if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
17852 			       NL80211_REGDOM_TYPE_WORLD))
17853 			goto nla_put_failure;
17854 	} else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
17855 		if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
17856 			       NL80211_REGDOM_TYPE_CUSTOM_WORLD))
17857 			goto nla_put_failure;
17858 	} else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
17859 		   request->intersect) {
17860 		if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
17861 			       NL80211_REGDOM_TYPE_INTERSECTION))
17862 			goto nla_put_failure;
17863 	} else {
17864 		if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
17865 			       NL80211_REGDOM_TYPE_COUNTRY) ||
17866 		    nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
17867 				   request->alpha2))
17868 			goto nla_put_failure;
17869 	}
17870 
17871 	if (request->wiphy_idx != WIPHY_IDX_INVALID) {
17872 		struct wiphy *wiphy = wiphy_idx_to_wiphy(request->wiphy_idx);
17873 
17874 		if (wiphy &&
17875 		    nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
17876 			goto nla_put_failure;
17877 
17878 		if (wiphy &&
17879 		    wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
17880 		    nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
17881 			goto nla_put_failure;
17882 	}
17883 
17884 	return true;
17885 
17886 nla_put_failure:
17887 	return false;
17888 }
17889 
17890 /*
17891  * This can happen on global regulatory changes or device specific settings
17892  * based on custom regulatory domains.
17893  */
nl80211_common_reg_change_event(enum nl80211_commands cmd_id,struct regulatory_request * request)17894 void nl80211_common_reg_change_event(enum nl80211_commands cmd_id,
17895 				     struct regulatory_request *request)
17896 {
17897 	struct sk_buff *msg;
17898 	void *hdr;
17899 
17900 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
17901 	if (!msg)
17902 		return;
17903 
17904 	hdr = nl80211hdr_put(msg, 0, 0, 0, cmd_id);
17905 	if (!hdr)
17906 		goto nla_put_failure;
17907 
17908 	if (!nl80211_reg_change_event_fill(msg, request))
17909 		goto nla_put_failure;
17910 
17911 	genlmsg_end(msg, hdr);
17912 
17913 	genlmsg_multicast_allns(&nl80211_fam, msg, 0,
17914 				NL80211_MCGRP_REGULATORY);
17915 
17916 	return;
17917 
17918 nla_put_failure:
17919 	nlmsg_free(msg);
17920 }
17921 
nl80211_send_mlme_event(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * buf,size_t len,enum nl80211_commands cmd,gfp_t gfp,int uapsd_queues,const u8 * req_ies,size_t req_ies_len,bool reconnect)17922 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
17923 				    struct net_device *netdev,
17924 				    const u8 *buf, size_t len,
17925 				    enum nl80211_commands cmd, gfp_t gfp,
17926 				    int uapsd_queues, const u8 *req_ies,
17927 				    size_t req_ies_len, bool reconnect)
17928 {
17929 	struct sk_buff *msg;
17930 	void *hdr;
17931 
17932 	msg = nlmsg_new(100 + len + req_ies_len, gfp);
17933 	if (!msg)
17934 		return;
17935 
17936 	hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
17937 	if (!hdr) {
17938 		nlmsg_free(msg);
17939 		return;
17940 	}
17941 
17942 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
17943 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
17944 	    nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
17945 	    (req_ies &&
17946 	     nla_put(msg, NL80211_ATTR_REQ_IE, req_ies_len, req_ies)))
17947 		goto nla_put_failure;
17948 
17949 	if (reconnect && nla_put_flag(msg, NL80211_ATTR_RECONNECT_REQUESTED))
17950 		goto nla_put_failure;
17951 
17952 	if (uapsd_queues >= 0) {
17953 		struct nlattr *nla_wmm =
17954 			nla_nest_start_noflag(msg, NL80211_ATTR_STA_WME);
17955 		if (!nla_wmm)
17956 			goto nla_put_failure;
17957 
17958 		if (nla_put_u8(msg, NL80211_STA_WME_UAPSD_QUEUES,
17959 			       uapsd_queues))
17960 			goto nla_put_failure;
17961 
17962 		nla_nest_end(msg, nla_wmm);
17963 	}
17964 
17965 	genlmsg_end(msg, hdr);
17966 
17967 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
17968 				NL80211_MCGRP_MLME, gfp);
17969 	return;
17970 
17971  nla_put_failure:
17972 	nlmsg_free(msg);
17973 }
17974 
nl80211_send_rx_auth(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * buf,size_t len,gfp_t gfp)17975 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
17976 			  struct net_device *netdev, const u8 *buf,
17977 			  size_t len, gfp_t gfp)
17978 {
17979 	nl80211_send_mlme_event(rdev, netdev, buf, len,
17980 				NL80211_CMD_AUTHENTICATE, gfp, -1, NULL, 0,
17981 				false);
17982 }
17983 
nl80211_send_rx_assoc(struct cfg80211_registered_device * rdev,struct net_device * netdev,struct cfg80211_rx_assoc_resp * data)17984 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
17985 			   struct net_device *netdev,
17986 			   struct cfg80211_rx_assoc_resp *data)
17987 {
17988 	nl80211_send_mlme_event(rdev, netdev, data->buf, data->len,
17989 				NL80211_CMD_ASSOCIATE, GFP_KERNEL,
17990 				data->uapsd_queues,
17991 				data->req_ies, data->req_ies_len, false);
17992 }
17993 
nl80211_send_deauth(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * buf,size_t len,bool reconnect,gfp_t gfp)17994 void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
17995 			 struct net_device *netdev, const u8 *buf,
17996 			 size_t len, bool reconnect, gfp_t gfp)
17997 {
17998 	nl80211_send_mlme_event(rdev, netdev, buf, len,
17999 				NL80211_CMD_DEAUTHENTICATE, gfp, -1, NULL, 0,
18000 				reconnect);
18001 }
18002 
nl80211_send_disassoc(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * buf,size_t len,bool reconnect,gfp_t gfp)18003 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
18004 			   struct net_device *netdev, const u8 *buf,
18005 			   size_t len, bool reconnect, gfp_t gfp)
18006 {
18007 	nl80211_send_mlme_event(rdev, netdev, buf, len,
18008 				NL80211_CMD_DISASSOCIATE, gfp, -1, NULL, 0,
18009 				reconnect);
18010 }
18011 
cfg80211_rx_unprot_mlme_mgmt(struct net_device * dev,const u8 * buf,size_t len)18012 void cfg80211_rx_unprot_mlme_mgmt(struct net_device *dev, const u8 *buf,
18013 				  size_t len)
18014 {
18015 	struct wireless_dev *wdev = dev->ieee80211_ptr;
18016 	struct wiphy *wiphy = wdev->wiphy;
18017 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
18018 	const struct ieee80211_mgmt *mgmt = (void *)buf;
18019 	u32 cmd;
18020 
18021 	if (WARN_ON(len < 2))
18022 		return;
18023 
18024 	if (ieee80211_is_deauth(mgmt->frame_control)) {
18025 		cmd = NL80211_CMD_UNPROT_DEAUTHENTICATE;
18026 	} else if (ieee80211_is_disassoc(mgmt->frame_control)) {
18027 		cmd = NL80211_CMD_UNPROT_DISASSOCIATE;
18028 	} else if (ieee80211_is_beacon(mgmt->frame_control)) {
18029 		if (wdev->unprot_beacon_reported &&
18030 		    elapsed_jiffies_msecs(wdev->unprot_beacon_reported) < 10000)
18031 			return;
18032 		cmd = NL80211_CMD_UNPROT_BEACON;
18033 		wdev->unprot_beacon_reported = jiffies;
18034 	} else {
18035 		return;
18036 	}
18037 
18038 	trace_cfg80211_rx_unprot_mlme_mgmt(dev, buf, len);
18039 	nl80211_send_mlme_event(rdev, dev, buf, len, cmd, GFP_ATOMIC, -1,
18040 				NULL, 0, false);
18041 }
18042 EXPORT_SYMBOL(cfg80211_rx_unprot_mlme_mgmt);
18043 
nl80211_send_mlme_timeout(struct cfg80211_registered_device * rdev,struct net_device * netdev,int cmd,const u8 * addr,gfp_t gfp)18044 static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
18045 				      struct net_device *netdev, int cmd,
18046 				      const u8 *addr, gfp_t gfp)
18047 {
18048 	struct sk_buff *msg;
18049 	void *hdr;
18050 
18051 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
18052 	if (!msg)
18053 		return;
18054 
18055 	hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
18056 	if (!hdr) {
18057 		nlmsg_free(msg);
18058 		return;
18059 	}
18060 
18061 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18062 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
18063 	    nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
18064 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
18065 		goto nla_put_failure;
18066 
18067 	genlmsg_end(msg, hdr);
18068 
18069 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18070 				NL80211_MCGRP_MLME, gfp);
18071 	return;
18072 
18073  nla_put_failure:
18074 	nlmsg_free(msg);
18075 }
18076 
nl80211_send_auth_timeout(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * addr,gfp_t gfp)18077 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
18078 			       struct net_device *netdev, const u8 *addr,
18079 			       gfp_t gfp)
18080 {
18081 	nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
18082 				  addr, gfp);
18083 }
18084 
nl80211_send_assoc_timeout(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * addr,gfp_t gfp)18085 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
18086 				struct net_device *netdev, const u8 *addr,
18087 				gfp_t gfp)
18088 {
18089 	nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
18090 				  addr, gfp);
18091 }
18092 
nl80211_send_connect_result(struct cfg80211_registered_device * rdev,struct net_device * netdev,struct cfg80211_connect_resp_params * cr,gfp_t gfp)18093 void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
18094 				 struct net_device *netdev,
18095 				 struct cfg80211_connect_resp_params *cr,
18096 				 gfp_t gfp)
18097 {
18098 	struct sk_buff *msg;
18099 	void *hdr;
18100 	unsigned int link;
18101 	size_t link_info_size = 0;
18102 	const u8 *connected_addr = cr->valid_links ?
18103 				   cr->ap_mld_addr : cr->links[0].bssid;
18104 
18105 	if (cr->valid_links) {
18106 		for_each_valid_link(cr, link) {
18107 			/* Nested attribute header */
18108 			link_info_size += NLA_HDRLEN;
18109 			/* Link ID */
18110 			link_info_size += nla_total_size(sizeof(u8));
18111 			link_info_size += cr->links[link].addr ?
18112 					  nla_total_size(ETH_ALEN) : 0;
18113 			link_info_size += (cr->links[link].bssid ||
18114 					   cr->links[link].bss) ?
18115 					  nla_total_size(ETH_ALEN) : 0;
18116 			link_info_size += nla_total_size(sizeof(u16));
18117 		}
18118 	}
18119 
18120 	msg = nlmsg_new(100 + cr->req_ie_len + cr->resp_ie_len +
18121 			cr->fils.kek_len + cr->fils.pmk_len +
18122 			(cr->fils.pmkid ? WLAN_PMKID_LEN : 0) + link_info_size,
18123 			gfp);
18124 	if (!msg)
18125 		return;
18126 
18127 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
18128 	if (!hdr) {
18129 		nlmsg_free(msg);
18130 		return;
18131 	}
18132 
18133 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18134 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
18135 	    (connected_addr &&
18136 	     nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, connected_addr)) ||
18137 	    nla_put_u16(msg, NL80211_ATTR_STATUS_CODE,
18138 			cr->status < 0 ? WLAN_STATUS_UNSPECIFIED_FAILURE :
18139 			cr->status) ||
18140 	    (cr->status < 0 &&
18141 	     (nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
18142 	      nla_put_u32(msg, NL80211_ATTR_TIMEOUT_REASON,
18143 			  cr->timeout_reason))) ||
18144 	    (cr->req_ie &&
18145 	     nla_put(msg, NL80211_ATTR_REQ_IE, cr->req_ie_len, cr->req_ie)) ||
18146 	    (cr->resp_ie &&
18147 	     nla_put(msg, NL80211_ATTR_RESP_IE, cr->resp_ie_len,
18148 		     cr->resp_ie)) ||
18149 	    (cr->fils.update_erp_next_seq_num &&
18150 	     nla_put_u16(msg, NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM,
18151 			 cr->fils.erp_next_seq_num)) ||
18152 	    (cr->status == WLAN_STATUS_SUCCESS &&
18153 	     ((cr->fils.kek &&
18154 	       nla_put(msg, NL80211_ATTR_FILS_KEK, cr->fils.kek_len,
18155 		       cr->fils.kek)) ||
18156 	      (cr->fils.pmk &&
18157 	       nla_put(msg, NL80211_ATTR_PMK, cr->fils.pmk_len, cr->fils.pmk)) ||
18158 	      (cr->fils.pmkid &&
18159 	       nla_put(msg, NL80211_ATTR_PMKID, WLAN_PMKID_LEN, cr->fils.pmkid)))))
18160 		goto nla_put_failure;
18161 
18162 	if (cr->valid_links) {
18163 		int i = 1;
18164 		struct nlattr *nested;
18165 
18166 		nested = nla_nest_start(msg, NL80211_ATTR_MLO_LINKS);
18167 		if (!nested)
18168 			goto nla_put_failure;
18169 
18170 		for_each_valid_link(cr, link) {
18171 			struct nlattr *nested_mlo_links;
18172 			const u8 *bssid = cr->links[link].bss ?
18173 					  cr->links[link].bss->bssid :
18174 					  cr->links[link].bssid;
18175 
18176 			nested_mlo_links = nla_nest_start(msg, i);
18177 			if (!nested_mlo_links)
18178 				goto nla_put_failure;
18179 
18180 			if (nla_put_u8(msg, NL80211_ATTR_MLO_LINK_ID, link) ||
18181 			    (bssid &&
18182 			     nla_put(msg, NL80211_ATTR_BSSID, ETH_ALEN, bssid)) ||
18183 			    (cr->links[link].addr &&
18184 			     nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN,
18185 				     cr->links[link].addr)) ||
18186 			    nla_put_u16(msg, NL80211_ATTR_STATUS_CODE,
18187 					cr->links[link].status))
18188 				goto nla_put_failure;
18189 
18190 			nla_nest_end(msg, nested_mlo_links);
18191 			i++;
18192 		}
18193 		nla_nest_end(msg, nested);
18194 	}
18195 
18196 	genlmsg_end(msg, hdr);
18197 
18198 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18199 				NL80211_MCGRP_MLME, gfp);
18200 	return;
18201 
18202  nla_put_failure:
18203 	nlmsg_free(msg);
18204 }
18205 
nl80211_send_roamed(struct cfg80211_registered_device * rdev,struct net_device * netdev,struct cfg80211_roam_info * info,gfp_t gfp)18206 void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
18207 			 struct net_device *netdev,
18208 			 struct cfg80211_roam_info *info, gfp_t gfp)
18209 {
18210 	struct sk_buff *msg;
18211 	void *hdr;
18212 	size_t link_info_size = 0;
18213 	unsigned int link;
18214 	const u8 *connected_addr = info->ap_mld_addr ?
18215 				   info->ap_mld_addr :
18216 				   (info->links[0].bss ?
18217 				    info->links[0].bss->bssid :
18218 				    info->links[0].bssid);
18219 
18220 	if (info->valid_links) {
18221 		for_each_valid_link(info, link) {
18222 			/* Nested attribute header */
18223 			link_info_size += NLA_HDRLEN;
18224 			/* Link ID */
18225 			link_info_size += nla_total_size(sizeof(u8));
18226 			link_info_size += info->links[link].addr ?
18227 					  nla_total_size(ETH_ALEN) : 0;
18228 			link_info_size += (info->links[link].bssid ||
18229 					   info->links[link].bss) ?
18230 					  nla_total_size(ETH_ALEN) : 0;
18231 		}
18232 	}
18233 
18234 	msg = nlmsg_new(100 + info->req_ie_len + info->resp_ie_len +
18235 			info->fils.kek_len + info->fils.pmk_len +
18236 			(info->fils.pmkid ? WLAN_PMKID_LEN : 0) +
18237 			link_info_size, gfp);
18238 	if (!msg)
18239 		return;
18240 
18241 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
18242 	if (!hdr) {
18243 		nlmsg_free(msg);
18244 		return;
18245 	}
18246 
18247 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18248 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
18249 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, connected_addr) ||
18250 	    (info->req_ie &&
18251 	     nla_put(msg, NL80211_ATTR_REQ_IE, info->req_ie_len,
18252 		     info->req_ie)) ||
18253 	    (info->resp_ie &&
18254 	     nla_put(msg, NL80211_ATTR_RESP_IE, info->resp_ie_len,
18255 		     info->resp_ie)) ||
18256 	    (info->fils.update_erp_next_seq_num &&
18257 	     nla_put_u16(msg, NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM,
18258 			 info->fils.erp_next_seq_num)) ||
18259 	    (info->fils.kek &&
18260 	     nla_put(msg, NL80211_ATTR_FILS_KEK, info->fils.kek_len,
18261 		     info->fils.kek)) ||
18262 	    (info->fils.pmk &&
18263 	     nla_put(msg, NL80211_ATTR_PMK, info->fils.pmk_len, info->fils.pmk)) ||
18264 	    (info->fils.pmkid &&
18265 	     nla_put(msg, NL80211_ATTR_PMKID, WLAN_PMKID_LEN, info->fils.pmkid)))
18266 		goto nla_put_failure;
18267 
18268 	if (info->valid_links) {
18269 		int i = 1;
18270 		struct nlattr *nested;
18271 
18272 		nested = nla_nest_start(msg, NL80211_ATTR_MLO_LINKS);
18273 		if (!nested)
18274 			goto nla_put_failure;
18275 
18276 		for_each_valid_link(info, link) {
18277 			struct nlattr *nested_mlo_links;
18278 			const u8 *bssid = info->links[link].bss ?
18279 					  info->links[link].bss->bssid :
18280 					  info->links[link].bssid;
18281 
18282 			nested_mlo_links = nla_nest_start(msg, i);
18283 			if (!nested_mlo_links)
18284 				goto nla_put_failure;
18285 
18286 			if (nla_put_u8(msg, NL80211_ATTR_MLO_LINK_ID, link) ||
18287 			    (bssid &&
18288 			     nla_put(msg, NL80211_ATTR_BSSID, ETH_ALEN, bssid)) ||
18289 			    (info->links[link].addr &&
18290 			     nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN,
18291 				     info->links[link].addr)))
18292 				goto nla_put_failure;
18293 
18294 			nla_nest_end(msg, nested_mlo_links);
18295 			i++;
18296 		}
18297 		nla_nest_end(msg, nested);
18298 	}
18299 
18300 	genlmsg_end(msg, hdr);
18301 
18302 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18303 				NL80211_MCGRP_MLME, gfp);
18304 	return;
18305 
18306  nla_put_failure:
18307 	nlmsg_free(msg);
18308 }
18309 
nl80211_send_port_authorized(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * bssid,const u8 * td_bitmap,u8 td_bitmap_len)18310 void nl80211_send_port_authorized(struct cfg80211_registered_device *rdev,
18311 				  struct net_device *netdev, const u8 *bssid,
18312 				  const u8 *td_bitmap, u8 td_bitmap_len)
18313 {
18314 	struct sk_buff *msg;
18315 	void *hdr;
18316 
18317 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
18318 	if (!msg)
18319 		return;
18320 
18321 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PORT_AUTHORIZED);
18322 	if (!hdr) {
18323 		nlmsg_free(msg);
18324 		return;
18325 	}
18326 
18327 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18328 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
18329 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
18330 		goto nla_put_failure;
18331 
18332 	if ((td_bitmap_len > 0) && td_bitmap)
18333 		if (nla_put(msg, NL80211_ATTR_TD_BITMAP,
18334 			    td_bitmap_len, td_bitmap))
18335 			goto nla_put_failure;
18336 
18337 	genlmsg_end(msg, hdr);
18338 
18339 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18340 				NL80211_MCGRP_MLME, GFP_KERNEL);
18341 	return;
18342 
18343  nla_put_failure:
18344 	nlmsg_free(msg);
18345 }
18346 
nl80211_send_disconnected(struct cfg80211_registered_device * rdev,struct net_device * netdev,u16 reason,const u8 * ie,size_t ie_len,bool from_ap)18347 void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
18348 			       struct net_device *netdev, u16 reason,
18349 			       const u8 *ie, size_t ie_len, bool from_ap)
18350 {
18351 	struct sk_buff *msg;
18352 	void *hdr;
18353 
18354 	msg = nlmsg_new(100 + ie_len, GFP_KERNEL);
18355 	if (!msg)
18356 		return;
18357 
18358 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
18359 	if (!hdr) {
18360 		nlmsg_free(msg);
18361 		return;
18362 	}
18363 
18364 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18365 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
18366 	    (reason &&
18367 	     nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
18368 	    (from_ap &&
18369 	     nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
18370 	    (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
18371 		goto nla_put_failure;
18372 
18373 	genlmsg_end(msg, hdr);
18374 
18375 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18376 				NL80211_MCGRP_MLME, GFP_KERNEL);
18377 	return;
18378 
18379  nla_put_failure:
18380 	nlmsg_free(msg);
18381 }
18382 
cfg80211_links_removed(struct net_device * dev,u16 link_mask)18383 void cfg80211_links_removed(struct net_device *dev, u16 link_mask)
18384 {
18385 	struct wireless_dev *wdev = dev->ieee80211_ptr;
18386 	struct wiphy *wiphy = wdev->wiphy;
18387 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
18388 	struct sk_buff *msg;
18389 	struct nlattr *links;
18390 	void *hdr;
18391 
18392 	ASSERT_WDEV_LOCK(wdev);
18393 	trace_cfg80211_links_removed(dev, link_mask);
18394 
18395 	if (WARN_ON(wdev->iftype != NL80211_IFTYPE_STATION &&
18396 		    wdev->iftype != NL80211_IFTYPE_P2P_CLIENT))
18397 		return;
18398 
18399 	if (WARN_ON(!wdev->valid_links || !link_mask ||
18400 		    (wdev->valid_links & link_mask) != link_mask ||
18401 		    wdev->valid_links == link_mask))
18402 		return;
18403 
18404 	cfg80211_wdev_release_link_bsses(wdev, link_mask);
18405 	wdev->valid_links &= ~link_mask;
18406 
18407 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
18408 	if (!msg)
18409 		return;
18410 
18411 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_LINKS_REMOVED);
18412 	if (!hdr) {
18413 		nlmsg_free(msg);
18414 		return;
18415 	}
18416 
18417 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18418 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
18419 		goto nla_put_failure;
18420 
18421 	links = nla_nest_start(msg, NL80211_ATTR_MLO_LINKS);
18422 	if (!links)
18423 		goto nla_put_failure;
18424 
18425 	while (link_mask) {
18426 		struct nlattr *link;
18427 		int link_id = __ffs(link_mask);
18428 
18429 		link = nla_nest_start(msg, link_id + 1);
18430 		if (!link)
18431 			goto nla_put_failure;
18432 
18433 		if (nla_put_u8(msg, NL80211_ATTR_MLO_LINK_ID, link_id))
18434 			goto nla_put_failure;
18435 
18436 		nla_nest_end(msg, link);
18437 		link_mask &= ~(1 << link_id);
18438 	}
18439 
18440 	nla_nest_end(msg, links);
18441 
18442 	genlmsg_end(msg, hdr);
18443 
18444 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18445 				NL80211_MCGRP_MLME, GFP_KERNEL);
18446 	return;
18447 
18448  nla_put_failure:
18449 	nlmsg_free(msg);
18450 }
18451 EXPORT_SYMBOL(cfg80211_links_removed);
18452 
nl80211_send_ibss_bssid(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * bssid,gfp_t gfp)18453 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
18454 			     struct net_device *netdev, const u8 *bssid,
18455 			     gfp_t gfp)
18456 {
18457 	struct sk_buff *msg;
18458 	void *hdr;
18459 
18460 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
18461 	if (!msg)
18462 		return;
18463 
18464 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
18465 	if (!hdr) {
18466 		nlmsg_free(msg);
18467 		return;
18468 	}
18469 
18470 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18471 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
18472 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
18473 		goto nla_put_failure;
18474 
18475 	genlmsg_end(msg, hdr);
18476 
18477 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18478 				NL80211_MCGRP_MLME, gfp);
18479 	return;
18480 
18481  nla_put_failure:
18482 	nlmsg_free(msg);
18483 }
18484 
cfg80211_notify_new_peer_candidate(struct net_device * dev,const u8 * addr,const u8 * ie,u8 ie_len,int sig_dbm,gfp_t gfp)18485 void cfg80211_notify_new_peer_candidate(struct net_device *dev, const u8 *addr,
18486 					const u8 *ie, u8 ie_len,
18487 					int sig_dbm, gfp_t gfp)
18488 {
18489 	struct wireless_dev *wdev = dev->ieee80211_ptr;
18490 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
18491 	struct sk_buff *msg;
18492 	void *hdr;
18493 
18494 	if (WARN_ON(wdev->iftype != NL80211_IFTYPE_MESH_POINT))
18495 		return;
18496 
18497 	trace_cfg80211_notify_new_peer_candidate(dev, addr);
18498 
18499 	msg = nlmsg_new(100 + ie_len, gfp);
18500 	if (!msg)
18501 		return;
18502 
18503 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
18504 	if (!hdr) {
18505 		nlmsg_free(msg);
18506 		return;
18507 	}
18508 
18509 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18510 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
18511 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
18512 	    (ie_len && ie &&
18513 	     nla_put(msg, NL80211_ATTR_IE, ie_len, ie)) ||
18514 	    (sig_dbm &&
18515 	     nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)))
18516 		goto nla_put_failure;
18517 
18518 	genlmsg_end(msg, hdr);
18519 
18520 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18521 				NL80211_MCGRP_MLME, gfp);
18522 	return;
18523 
18524  nla_put_failure:
18525 	nlmsg_free(msg);
18526 }
18527 EXPORT_SYMBOL(cfg80211_notify_new_peer_candidate);
18528 
nl80211_michael_mic_failure(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * addr,enum nl80211_key_type key_type,int key_id,const u8 * tsc,gfp_t gfp)18529 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
18530 				 struct net_device *netdev, const u8 *addr,
18531 				 enum nl80211_key_type key_type, int key_id,
18532 				 const u8 *tsc, gfp_t gfp)
18533 {
18534 	struct sk_buff *msg;
18535 	void *hdr;
18536 
18537 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
18538 	if (!msg)
18539 		return;
18540 
18541 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
18542 	if (!hdr) {
18543 		nlmsg_free(msg);
18544 		return;
18545 	}
18546 
18547 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18548 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
18549 	    (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
18550 	    nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
18551 	    (key_id != -1 &&
18552 	     nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
18553 	    (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
18554 		goto nla_put_failure;
18555 
18556 	genlmsg_end(msg, hdr);
18557 
18558 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18559 				NL80211_MCGRP_MLME, gfp);
18560 	return;
18561 
18562  nla_put_failure:
18563 	nlmsg_free(msg);
18564 }
18565 
nl80211_send_beacon_hint_event(struct wiphy * wiphy,struct ieee80211_channel * channel_before,struct ieee80211_channel * channel_after)18566 void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
18567 				    struct ieee80211_channel *channel_before,
18568 				    struct ieee80211_channel *channel_after)
18569 {
18570 	struct sk_buff *msg;
18571 	void *hdr;
18572 	struct nlattr *nl_freq;
18573 
18574 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
18575 	if (!msg)
18576 		return;
18577 
18578 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
18579 	if (!hdr) {
18580 		nlmsg_free(msg);
18581 		return;
18582 	}
18583 
18584 	/*
18585 	 * Since we are applying the beacon hint to a wiphy we know its
18586 	 * wiphy_idx is valid
18587 	 */
18588 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
18589 		goto nla_put_failure;
18590 
18591 	/* Before */
18592 	nl_freq = nla_nest_start_noflag(msg, NL80211_ATTR_FREQ_BEFORE);
18593 	if (!nl_freq)
18594 		goto nla_put_failure;
18595 
18596 	if (nl80211_msg_put_channel(msg, wiphy, channel_before, false))
18597 		goto nla_put_failure;
18598 	nla_nest_end(msg, nl_freq);
18599 
18600 	/* After */
18601 	nl_freq = nla_nest_start_noflag(msg, NL80211_ATTR_FREQ_AFTER);
18602 	if (!nl_freq)
18603 		goto nla_put_failure;
18604 
18605 	if (nl80211_msg_put_channel(msg, wiphy, channel_after, false))
18606 		goto nla_put_failure;
18607 	nla_nest_end(msg, nl_freq);
18608 
18609 	genlmsg_end(msg, hdr);
18610 
18611 	genlmsg_multicast_allns(&nl80211_fam, msg, 0,
18612 				NL80211_MCGRP_REGULATORY);
18613 
18614 	return;
18615 
18616 nla_put_failure:
18617 	nlmsg_free(msg);
18618 }
18619 
nl80211_send_remain_on_chan_event(int cmd,struct cfg80211_registered_device * rdev,struct wireless_dev * wdev,u64 cookie,struct ieee80211_channel * chan,unsigned int duration,gfp_t gfp)18620 static void nl80211_send_remain_on_chan_event(
18621 	int cmd, struct cfg80211_registered_device *rdev,
18622 	struct wireless_dev *wdev, u64 cookie,
18623 	struct ieee80211_channel *chan,
18624 	unsigned int duration, gfp_t gfp)
18625 {
18626 	struct sk_buff *msg;
18627 	void *hdr;
18628 
18629 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
18630 	if (!msg)
18631 		return;
18632 
18633 	hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
18634 	if (!hdr) {
18635 		nlmsg_free(msg);
18636 		return;
18637 	}
18638 
18639 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18640 	    (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
18641 					 wdev->netdev->ifindex)) ||
18642 	    nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
18643 			      NL80211_ATTR_PAD) ||
18644 	    nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
18645 	    nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
18646 			NL80211_CHAN_NO_HT) ||
18647 	    nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
18648 			      NL80211_ATTR_PAD))
18649 		goto nla_put_failure;
18650 
18651 	if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
18652 	    nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
18653 		goto nla_put_failure;
18654 
18655 	genlmsg_end(msg, hdr);
18656 
18657 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18658 				NL80211_MCGRP_MLME, gfp);
18659 	return;
18660 
18661  nla_put_failure:
18662 	nlmsg_free(msg);
18663 }
18664 
cfg80211_assoc_comeback(struct net_device * netdev,const u8 * ap_addr,u32 timeout)18665 void cfg80211_assoc_comeback(struct net_device *netdev,
18666 			     const u8 *ap_addr, u32 timeout)
18667 {
18668 	struct wireless_dev *wdev = netdev->ieee80211_ptr;
18669 	struct wiphy *wiphy = wdev->wiphy;
18670 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
18671 	struct sk_buff *msg;
18672 	void *hdr;
18673 
18674 	trace_cfg80211_assoc_comeback(wdev, ap_addr, timeout);
18675 
18676 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
18677 	if (!msg)
18678 		return;
18679 
18680 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ASSOC_COMEBACK);
18681 	if (!hdr) {
18682 		nlmsg_free(msg);
18683 		return;
18684 	}
18685 
18686 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18687 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
18688 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, ap_addr) ||
18689 	    nla_put_u32(msg, NL80211_ATTR_TIMEOUT, timeout))
18690 		goto nla_put_failure;
18691 
18692 	genlmsg_end(msg, hdr);
18693 
18694 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18695 				NL80211_MCGRP_MLME, GFP_KERNEL);
18696 	return;
18697 
18698  nla_put_failure:
18699 	nlmsg_free(msg);
18700 }
18701 EXPORT_SYMBOL(cfg80211_assoc_comeback);
18702 
cfg80211_ready_on_channel(struct wireless_dev * wdev,u64 cookie,struct ieee80211_channel * chan,unsigned int duration,gfp_t gfp)18703 void cfg80211_ready_on_channel(struct wireless_dev *wdev, u64 cookie,
18704 			       struct ieee80211_channel *chan,
18705 			       unsigned int duration, gfp_t gfp)
18706 {
18707 	struct wiphy *wiphy = wdev->wiphy;
18708 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
18709 
18710 	trace_cfg80211_ready_on_channel(wdev, cookie, chan, duration);
18711 	nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
18712 					  rdev, wdev, cookie, chan,
18713 					  duration, gfp);
18714 }
18715 EXPORT_SYMBOL(cfg80211_ready_on_channel);
18716 
cfg80211_remain_on_channel_expired(struct wireless_dev * wdev,u64 cookie,struct ieee80211_channel * chan,gfp_t gfp)18717 void cfg80211_remain_on_channel_expired(struct wireless_dev *wdev, u64 cookie,
18718 					struct ieee80211_channel *chan,
18719 					gfp_t gfp)
18720 {
18721 	struct wiphy *wiphy = wdev->wiphy;
18722 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
18723 
18724 	trace_cfg80211_ready_on_channel_expired(wdev, cookie, chan);
18725 	nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
18726 					  rdev, wdev, cookie, chan, 0, gfp);
18727 }
18728 EXPORT_SYMBOL(cfg80211_remain_on_channel_expired);
18729 
cfg80211_tx_mgmt_expired(struct wireless_dev * wdev,u64 cookie,struct ieee80211_channel * chan,gfp_t gfp)18730 void cfg80211_tx_mgmt_expired(struct wireless_dev *wdev, u64 cookie,
18731 					struct ieee80211_channel *chan,
18732 					gfp_t gfp)
18733 {
18734 	struct wiphy *wiphy = wdev->wiphy;
18735 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
18736 
18737 	trace_cfg80211_tx_mgmt_expired(wdev, cookie, chan);
18738 	nl80211_send_remain_on_chan_event(NL80211_CMD_FRAME_WAIT_CANCEL,
18739 					  rdev, wdev, cookie, chan, 0, gfp);
18740 }
18741 EXPORT_SYMBOL(cfg80211_tx_mgmt_expired);
18742 
cfg80211_new_sta(struct net_device * dev,const u8 * mac_addr,struct station_info * sinfo,gfp_t gfp)18743 void cfg80211_new_sta(struct net_device *dev, const u8 *mac_addr,
18744 		      struct station_info *sinfo, gfp_t gfp)
18745 {
18746 	struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
18747 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
18748 	struct sk_buff *msg;
18749 
18750 	trace_cfg80211_new_sta(dev, mac_addr, sinfo);
18751 
18752 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
18753 	if (!msg)
18754 		return;
18755 
18756 	if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION, 0, 0, 0,
18757 				 rdev, dev, mac_addr, sinfo) < 0) {
18758 		nlmsg_free(msg);
18759 		return;
18760 	}
18761 
18762 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18763 				NL80211_MCGRP_MLME, gfp);
18764 }
18765 EXPORT_SYMBOL(cfg80211_new_sta);
18766 
cfg80211_del_sta_sinfo(struct net_device * dev,const u8 * mac_addr,struct station_info * sinfo,gfp_t gfp)18767 void cfg80211_del_sta_sinfo(struct net_device *dev, const u8 *mac_addr,
18768 			    struct station_info *sinfo, gfp_t gfp)
18769 {
18770 	struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
18771 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
18772 	struct sk_buff *msg;
18773 	struct station_info empty_sinfo = {};
18774 
18775 	if (!sinfo)
18776 		sinfo = &empty_sinfo;
18777 
18778 	trace_cfg80211_del_sta(dev, mac_addr);
18779 
18780 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
18781 	if (!msg) {
18782 		cfg80211_sinfo_release_content(sinfo);
18783 		return;
18784 	}
18785 
18786 	if (nl80211_send_station(msg, NL80211_CMD_DEL_STATION, 0, 0, 0,
18787 				 rdev, dev, mac_addr, sinfo) < 0) {
18788 		nlmsg_free(msg);
18789 		return;
18790 	}
18791 
18792 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18793 				NL80211_MCGRP_MLME, gfp);
18794 }
18795 EXPORT_SYMBOL(cfg80211_del_sta_sinfo);
18796 
cfg80211_conn_failed(struct net_device * dev,const u8 * mac_addr,enum nl80211_connect_failed_reason reason,gfp_t gfp)18797 void cfg80211_conn_failed(struct net_device *dev, const u8 *mac_addr,
18798 			  enum nl80211_connect_failed_reason reason,
18799 			  gfp_t gfp)
18800 {
18801 	struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
18802 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
18803 	struct sk_buff *msg;
18804 	void *hdr;
18805 
18806 	msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
18807 	if (!msg)
18808 		return;
18809 
18810 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
18811 	if (!hdr) {
18812 		nlmsg_free(msg);
18813 		return;
18814 	}
18815 
18816 	if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
18817 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
18818 	    nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
18819 		goto nla_put_failure;
18820 
18821 	genlmsg_end(msg, hdr);
18822 
18823 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
18824 				NL80211_MCGRP_MLME, gfp);
18825 	return;
18826 
18827  nla_put_failure:
18828 	nlmsg_free(msg);
18829 }
18830 EXPORT_SYMBOL(cfg80211_conn_failed);
18831 
__nl80211_unexpected_frame(struct net_device * dev,u8 cmd,const u8 * addr,gfp_t gfp)18832 static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
18833 				       const u8 *addr, gfp_t gfp)
18834 {
18835 	struct wireless_dev *wdev = dev->ieee80211_ptr;
18836 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
18837 	struct sk_buff *msg;
18838 	void *hdr;
18839 	u32 nlportid = READ_ONCE(wdev->ap_unexpected_nlportid);
18840 
18841 	if (!nlportid)
18842 		return false;
18843 
18844 	msg = nlmsg_new(100, gfp);
18845 	if (!msg)
18846 		return true;
18847 
18848 	hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
18849 	if (!hdr) {
18850 		nlmsg_free(msg);
18851 		return true;
18852 	}
18853 
18854 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18855 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
18856 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
18857 		goto nla_put_failure;
18858 
18859 	genlmsg_end(msg, hdr);
18860 	genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
18861 	return true;
18862 
18863  nla_put_failure:
18864 	nlmsg_free(msg);
18865 	return true;
18866 }
18867 
cfg80211_rx_spurious_frame(struct net_device * dev,const u8 * addr,gfp_t gfp)18868 bool cfg80211_rx_spurious_frame(struct net_device *dev,
18869 				const u8 *addr, gfp_t gfp)
18870 {
18871 	struct wireless_dev *wdev = dev->ieee80211_ptr;
18872 	bool ret;
18873 
18874 	trace_cfg80211_rx_spurious_frame(dev, addr);
18875 
18876 	if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
18877 		    wdev->iftype != NL80211_IFTYPE_P2P_GO)) {
18878 		trace_cfg80211_return_bool(false);
18879 		return false;
18880 	}
18881 	ret = __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
18882 					 addr, gfp);
18883 	trace_cfg80211_return_bool(ret);
18884 	return ret;
18885 }
18886 EXPORT_SYMBOL(cfg80211_rx_spurious_frame);
18887 
cfg80211_rx_unexpected_4addr_frame(struct net_device * dev,const u8 * addr,gfp_t gfp)18888 bool cfg80211_rx_unexpected_4addr_frame(struct net_device *dev,
18889 					const u8 *addr, gfp_t gfp)
18890 {
18891 	struct wireless_dev *wdev = dev->ieee80211_ptr;
18892 	bool ret;
18893 
18894 	trace_cfg80211_rx_unexpected_4addr_frame(dev, addr);
18895 
18896 	if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
18897 		    wdev->iftype != NL80211_IFTYPE_P2P_GO &&
18898 		    wdev->iftype != NL80211_IFTYPE_AP_VLAN)) {
18899 		trace_cfg80211_return_bool(false);
18900 		return false;
18901 	}
18902 	ret = __nl80211_unexpected_frame(dev,
18903 					 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
18904 					 addr, gfp);
18905 	trace_cfg80211_return_bool(ret);
18906 	return ret;
18907 }
18908 EXPORT_SYMBOL(cfg80211_rx_unexpected_4addr_frame);
18909 
nl80211_send_mgmt(struct cfg80211_registered_device * rdev,struct wireless_dev * wdev,u32 nlportid,struct cfg80211_rx_info * info,gfp_t gfp)18910 int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
18911 		      struct wireless_dev *wdev, u32 nlportid,
18912 		      struct cfg80211_rx_info *info, gfp_t gfp)
18913 {
18914 	struct net_device *netdev = wdev->netdev;
18915 	struct sk_buff *msg;
18916 	void *hdr;
18917 
18918 	msg = nlmsg_new(100 + info->len, gfp);
18919 	if (!msg)
18920 		return -ENOMEM;
18921 
18922 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
18923 	if (!hdr) {
18924 		nlmsg_free(msg);
18925 		return -ENOMEM;
18926 	}
18927 
18928 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18929 	    (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
18930 					netdev->ifindex)) ||
18931 	    nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
18932 			      NL80211_ATTR_PAD) ||
18933 	    (info->have_link_id &&
18934 	     nla_put_u8(msg, NL80211_ATTR_MLO_LINK_ID, info->link_id)) ||
18935 	    nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, KHZ_TO_MHZ(info->freq)) ||
18936 	    nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ_OFFSET, info->freq % 1000) ||
18937 	    (info->sig_dbm &&
18938 	     nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, info->sig_dbm)) ||
18939 	    nla_put(msg, NL80211_ATTR_FRAME, info->len, info->buf) ||
18940 	    (info->flags &&
18941 	     nla_put_u32(msg, NL80211_ATTR_RXMGMT_FLAGS, info->flags)) ||
18942 	    (info->rx_tstamp && nla_put_u64_64bit(msg,
18943 						  NL80211_ATTR_RX_HW_TIMESTAMP,
18944 						  info->rx_tstamp,
18945 						  NL80211_ATTR_PAD)) ||
18946 	    (info->ack_tstamp && nla_put_u64_64bit(msg,
18947 						   NL80211_ATTR_TX_HW_TIMESTAMP,
18948 						   info->ack_tstamp,
18949 						   NL80211_ATTR_PAD)))
18950 		goto nla_put_failure;
18951 
18952 	genlmsg_end(msg, hdr);
18953 
18954 	return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
18955 
18956  nla_put_failure:
18957 	nlmsg_free(msg);
18958 	return -ENOBUFS;
18959 }
18960 
nl80211_frame_tx_status(struct wireless_dev * wdev,struct cfg80211_tx_status * status,gfp_t gfp,enum nl80211_commands command)18961 static void nl80211_frame_tx_status(struct wireless_dev *wdev,
18962 				    struct cfg80211_tx_status *status,
18963 				    gfp_t gfp, enum nl80211_commands command)
18964 {
18965 	struct wiphy *wiphy = wdev->wiphy;
18966 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
18967 	struct net_device *netdev = wdev->netdev;
18968 	struct sk_buff *msg;
18969 	void *hdr;
18970 
18971 	if (command == NL80211_CMD_FRAME_TX_STATUS)
18972 		trace_cfg80211_mgmt_tx_status(wdev, status->cookie,
18973 					      status->ack);
18974 	else
18975 		trace_cfg80211_control_port_tx_status(wdev, status->cookie,
18976 						      status->ack);
18977 
18978 	msg = nlmsg_new(100 + status->len, gfp);
18979 	if (!msg)
18980 		return;
18981 
18982 	hdr = nl80211hdr_put(msg, 0, 0, 0, command);
18983 	if (!hdr) {
18984 		nlmsg_free(msg);
18985 		return;
18986 	}
18987 
18988 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
18989 	    (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
18990 				   netdev->ifindex)) ||
18991 	    nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
18992 			      NL80211_ATTR_PAD) ||
18993 	    nla_put(msg, NL80211_ATTR_FRAME, status->len, status->buf) ||
18994 	    nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, status->cookie,
18995 			      NL80211_ATTR_PAD) ||
18996 	    (status->ack && nla_put_flag(msg, NL80211_ATTR_ACK)) ||
18997 	    (status->tx_tstamp &&
18998 	     nla_put_u64_64bit(msg, NL80211_ATTR_TX_HW_TIMESTAMP,
18999 			       status->tx_tstamp, NL80211_ATTR_PAD)) ||
19000 	    (status->ack_tstamp &&
19001 	     nla_put_u64_64bit(msg, NL80211_ATTR_RX_HW_TIMESTAMP,
19002 			       status->ack_tstamp, NL80211_ATTR_PAD)))
19003 		goto nla_put_failure;
19004 
19005 	genlmsg_end(msg, hdr);
19006 
19007 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
19008 				NL80211_MCGRP_MLME, gfp);
19009 	return;
19010 
19011 nla_put_failure:
19012 	nlmsg_free(msg);
19013 }
19014 
cfg80211_control_port_tx_status(struct wireless_dev * wdev,u64 cookie,const u8 * buf,size_t len,bool ack,gfp_t gfp)19015 void cfg80211_control_port_tx_status(struct wireless_dev *wdev, u64 cookie,
19016 				     const u8 *buf, size_t len, bool ack,
19017 				     gfp_t gfp)
19018 {
19019 	struct cfg80211_tx_status status = {
19020 		.cookie = cookie,
19021 		.buf = buf,
19022 		.len = len,
19023 		.ack = ack
19024 	};
19025 
19026 	nl80211_frame_tx_status(wdev, &status, gfp,
19027 				NL80211_CMD_CONTROL_PORT_FRAME_TX_STATUS);
19028 }
19029 EXPORT_SYMBOL(cfg80211_control_port_tx_status);
19030 
cfg80211_mgmt_tx_status_ext(struct wireless_dev * wdev,struct cfg80211_tx_status * status,gfp_t gfp)19031 void cfg80211_mgmt_tx_status_ext(struct wireless_dev *wdev,
19032 				 struct cfg80211_tx_status *status, gfp_t gfp)
19033 {
19034 	nl80211_frame_tx_status(wdev, status, gfp, NL80211_CMD_FRAME_TX_STATUS);
19035 }
19036 EXPORT_SYMBOL(cfg80211_mgmt_tx_status_ext);
19037 
__nl80211_rx_control_port(struct net_device * dev,struct sk_buff * skb,bool unencrypted,int link_id,gfp_t gfp)19038 static int __nl80211_rx_control_port(struct net_device *dev,
19039 				     struct sk_buff *skb,
19040 				     bool unencrypted,
19041 				     int link_id,
19042 				     gfp_t gfp)
19043 {
19044 	struct wireless_dev *wdev = dev->ieee80211_ptr;
19045 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
19046 	struct ethhdr *ehdr = eth_hdr(skb);
19047 	const u8 *addr = ehdr->h_source;
19048 	u16 proto = be16_to_cpu(skb->protocol);
19049 	struct sk_buff *msg;
19050 	void *hdr;
19051 	struct nlattr *frame;
19052 
19053 	u32 nlportid = READ_ONCE(wdev->conn_owner_nlportid);
19054 
19055 	if (!nlportid)
19056 		return -ENOENT;
19057 
19058 	msg = nlmsg_new(100 + skb->len, gfp);
19059 	if (!msg)
19060 		return -ENOMEM;
19061 
19062 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONTROL_PORT_FRAME);
19063 	if (!hdr) {
19064 		nlmsg_free(msg);
19065 		return -ENOBUFS;
19066 	}
19067 
19068 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
19069 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
19070 	    nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
19071 			      NL80211_ATTR_PAD) ||
19072 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
19073 	    nla_put_u16(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE, proto) ||
19074 	    (link_id >= 0 &&
19075 	     nla_put_u8(msg, NL80211_ATTR_MLO_LINK_ID, link_id)) ||
19076 	    (unencrypted && nla_put_flag(msg,
19077 					 NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT)))
19078 		goto nla_put_failure;
19079 
19080 	frame = nla_reserve(msg, NL80211_ATTR_FRAME, skb->len);
19081 	if (!frame)
19082 		goto nla_put_failure;
19083 
19084 	skb_copy_bits(skb, 0, nla_data(frame), skb->len);
19085 	genlmsg_end(msg, hdr);
19086 
19087 	return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
19088 
19089  nla_put_failure:
19090 	nlmsg_free(msg);
19091 	return -ENOBUFS;
19092 }
19093 
cfg80211_rx_control_port(struct net_device * dev,struct sk_buff * skb,bool unencrypted,int link_id)19094 bool cfg80211_rx_control_port(struct net_device *dev, struct sk_buff *skb,
19095 			      bool unencrypted, int link_id)
19096 {
19097 	int ret;
19098 
19099 	trace_cfg80211_rx_control_port(dev, skb, unencrypted, link_id);
19100 	ret = __nl80211_rx_control_port(dev, skb, unencrypted, link_id,
19101 					GFP_ATOMIC);
19102 	trace_cfg80211_return_bool(ret == 0);
19103 	return ret == 0;
19104 }
19105 EXPORT_SYMBOL(cfg80211_rx_control_port);
19106 
cfg80211_prepare_cqm(struct net_device * dev,const char * mac,gfp_t gfp)19107 static struct sk_buff *cfg80211_prepare_cqm(struct net_device *dev,
19108 					    const char *mac, gfp_t gfp)
19109 {
19110 	struct wireless_dev *wdev = dev->ieee80211_ptr;
19111 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
19112 	struct sk_buff *msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
19113 	void **cb;
19114 
19115 	if (!msg)
19116 		return NULL;
19117 
19118 	cb = (void **)msg->cb;
19119 
19120 	cb[0] = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
19121 	if (!cb[0]) {
19122 		nlmsg_free(msg);
19123 		return NULL;
19124 	}
19125 
19126 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
19127 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
19128 		goto nla_put_failure;
19129 
19130 	if (mac && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac))
19131 		goto nla_put_failure;
19132 
19133 	cb[1] = nla_nest_start_noflag(msg, NL80211_ATTR_CQM);
19134 	if (!cb[1])
19135 		goto nla_put_failure;
19136 
19137 	cb[2] = rdev;
19138 
19139 	return msg;
19140  nla_put_failure:
19141 	nlmsg_free(msg);
19142 	return NULL;
19143 }
19144 
cfg80211_send_cqm(struct sk_buff * msg,gfp_t gfp)19145 static void cfg80211_send_cqm(struct sk_buff *msg, gfp_t gfp)
19146 {
19147 	void **cb = (void **)msg->cb;
19148 	struct cfg80211_registered_device *rdev = cb[2];
19149 
19150 	nla_nest_end(msg, cb[1]);
19151 	genlmsg_end(msg, cb[0]);
19152 
19153 	memset(msg->cb, 0, sizeof(msg->cb));
19154 
19155 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
19156 				NL80211_MCGRP_MLME, gfp);
19157 }
19158 
cfg80211_cqm_rssi_notify(struct net_device * dev,enum nl80211_cqm_rssi_threshold_event rssi_event,s32 rssi_level,gfp_t gfp)19159 void cfg80211_cqm_rssi_notify(struct net_device *dev,
19160 			      enum nl80211_cqm_rssi_threshold_event rssi_event,
19161 			      s32 rssi_level, gfp_t gfp)
19162 {
19163 	struct wireless_dev *wdev = dev->ieee80211_ptr;
19164 	struct cfg80211_cqm_config *cqm_config;
19165 
19166 	trace_cfg80211_cqm_rssi_notify(dev, rssi_event, rssi_level);
19167 
19168 	if (WARN_ON(rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW &&
19169 		    rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH))
19170 		return;
19171 
19172 	rcu_read_lock();
19173 	cqm_config = rcu_dereference(wdev->cqm_config);
19174 	if (cqm_config) {
19175 		cqm_config->last_rssi_event_value = rssi_level;
19176 		cqm_config->last_rssi_event_type = rssi_event;
19177 		wiphy_work_queue(wdev->wiphy, &wdev->cqm_rssi_work);
19178 	}
19179 	rcu_read_unlock();
19180 }
19181 EXPORT_SYMBOL(cfg80211_cqm_rssi_notify);
19182 
cfg80211_cqm_rssi_notify_work(struct wiphy * wiphy,struct wiphy_work * work)19183 void cfg80211_cqm_rssi_notify_work(struct wiphy *wiphy, struct wiphy_work *work)
19184 {
19185 	struct wireless_dev *wdev = container_of(work, struct wireless_dev,
19186 						 cqm_rssi_work);
19187 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
19188 	enum nl80211_cqm_rssi_threshold_event rssi_event;
19189 	struct cfg80211_cqm_config *cqm_config;
19190 	struct sk_buff *msg;
19191 	s32 rssi_level;
19192 
19193 	wdev_lock(wdev);
19194 	cqm_config = rcu_dereference_protected(wdev->cqm_config,
19195 					       lockdep_is_held(&wdev->mtx));
19196 	if (!cqm_config)
19197 		goto unlock;
19198 
19199 	if (cqm_config->use_range_api)
19200 		cfg80211_cqm_rssi_update(rdev, wdev->netdev, cqm_config);
19201 
19202 	rssi_level = cqm_config->last_rssi_event_value;
19203 	rssi_event = cqm_config->last_rssi_event_type;
19204 
19205 	msg = cfg80211_prepare_cqm(wdev->netdev, NULL, GFP_KERNEL);
19206 	if (!msg)
19207 		goto unlock;
19208 
19209 	if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
19210 			rssi_event))
19211 		goto nla_put_failure;
19212 
19213 	if (rssi_level && nla_put_s32(msg, NL80211_ATTR_CQM_RSSI_LEVEL,
19214 				      rssi_level))
19215 		goto nla_put_failure;
19216 
19217 	cfg80211_send_cqm(msg, GFP_KERNEL);
19218 
19219 	goto unlock;
19220 
19221  nla_put_failure:
19222 	nlmsg_free(msg);
19223  unlock:
19224 	wdev_unlock(wdev);
19225 }
19226 
cfg80211_cqm_txe_notify(struct net_device * dev,const u8 * peer,u32 num_packets,u32 rate,u32 intvl,gfp_t gfp)19227 void cfg80211_cqm_txe_notify(struct net_device *dev,
19228 			     const u8 *peer, u32 num_packets,
19229 			     u32 rate, u32 intvl, gfp_t gfp)
19230 {
19231 	struct sk_buff *msg;
19232 
19233 	msg = cfg80211_prepare_cqm(dev, peer, gfp);
19234 	if (!msg)
19235 		return;
19236 
19237 	if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
19238 		goto nla_put_failure;
19239 
19240 	if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
19241 		goto nla_put_failure;
19242 
19243 	if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
19244 		goto nla_put_failure;
19245 
19246 	cfg80211_send_cqm(msg, gfp);
19247 	return;
19248 
19249  nla_put_failure:
19250 	nlmsg_free(msg);
19251 }
19252 EXPORT_SYMBOL(cfg80211_cqm_txe_notify);
19253 
cfg80211_cqm_pktloss_notify(struct net_device * dev,const u8 * peer,u32 num_packets,gfp_t gfp)19254 void cfg80211_cqm_pktloss_notify(struct net_device *dev,
19255 				 const u8 *peer, u32 num_packets, gfp_t gfp)
19256 {
19257 	struct sk_buff *msg;
19258 
19259 	trace_cfg80211_cqm_pktloss_notify(dev, peer, num_packets);
19260 
19261 	msg = cfg80211_prepare_cqm(dev, peer, gfp);
19262 	if (!msg)
19263 		return;
19264 
19265 	if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
19266 		goto nla_put_failure;
19267 
19268 	cfg80211_send_cqm(msg, gfp);
19269 	return;
19270 
19271  nla_put_failure:
19272 	nlmsg_free(msg);
19273 }
19274 EXPORT_SYMBOL(cfg80211_cqm_pktloss_notify);
19275 
cfg80211_cqm_beacon_loss_notify(struct net_device * dev,gfp_t gfp)19276 void cfg80211_cqm_beacon_loss_notify(struct net_device *dev, gfp_t gfp)
19277 {
19278 	struct sk_buff *msg;
19279 
19280 	msg = cfg80211_prepare_cqm(dev, NULL, gfp);
19281 	if (!msg)
19282 		return;
19283 
19284 	if (nla_put_flag(msg, NL80211_ATTR_CQM_BEACON_LOSS_EVENT))
19285 		goto nla_put_failure;
19286 
19287 	cfg80211_send_cqm(msg, gfp);
19288 	return;
19289 
19290  nla_put_failure:
19291 	nlmsg_free(msg);
19292 }
19293 EXPORT_SYMBOL(cfg80211_cqm_beacon_loss_notify);
19294 
nl80211_gtk_rekey_notify(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * bssid,const u8 * replay_ctr,gfp_t gfp)19295 static void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
19296 				     struct net_device *netdev, const u8 *bssid,
19297 				     const u8 *replay_ctr, gfp_t gfp)
19298 {
19299 	struct sk_buff *msg;
19300 	struct nlattr *rekey_attr;
19301 	void *hdr;
19302 
19303 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
19304 	if (!msg)
19305 		return;
19306 
19307 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
19308 	if (!hdr) {
19309 		nlmsg_free(msg);
19310 		return;
19311 	}
19312 
19313 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
19314 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
19315 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
19316 		goto nla_put_failure;
19317 
19318 	rekey_attr = nla_nest_start_noflag(msg, NL80211_ATTR_REKEY_DATA);
19319 	if (!rekey_attr)
19320 		goto nla_put_failure;
19321 
19322 	if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
19323 		    NL80211_REPLAY_CTR_LEN, replay_ctr))
19324 		goto nla_put_failure;
19325 
19326 	nla_nest_end(msg, rekey_attr);
19327 
19328 	genlmsg_end(msg, hdr);
19329 
19330 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
19331 				NL80211_MCGRP_MLME, gfp);
19332 	return;
19333 
19334  nla_put_failure:
19335 	nlmsg_free(msg);
19336 }
19337 
cfg80211_gtk_rekey_notify(struct net_device * dev,const u8 * bssid,const u8 * replay_ctr,gfp_t gfp)19338 void cfg80211_gtk_rekey_notify(struct net_device *dev, const u8 *bssid,
19339 			       const u8 *replay_ctr, gfp_t gfp)
19340 {
19341 	struct wireless_dev *wdev = dev->ieee80211_ptr;
19342 	struct wiphy *wiphy = wdev->wiphy;
19343 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
19344 
19345 	trace_cfg80211_gtk_rekey_notify(dev, bssid);
19346 	nl80211_gtk_rekey_notify(rdev, dev, bssid, replay_ctr, gfp);
19347 }
19348 EXPORT_SYMBOL(cfg80211_gtk_rekey_notify);
19349 
19350 static void
nl80211_pmksa_candidate_notify(struct cfg80211_registered_device * rdev,struct net_device * netdev,int index,const u8 * bssid,bool preauth,gfp_t gfp)19351 nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
19352 			       struct net_device *netdev, int index,
19353 			       const u8 *bssid, bool preauth, gfp_t gfp)
19354 {
19355 	struct sk_buff *msg;
19356 	struct nlattr *attr;
19357 	void *hdr;
19358 
19359 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
19360 	if (!msg)
19361 		return;
19362 
19363 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
19364 	if (!hdr) {
19365 		nlmsg_free(msg);
19366 		return;
19367 	}
19368 
19369 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
19370 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
19371 		goto nla_put_failure;
19372 
19373 	attr = nla_nest_start_noflag(msg, NL80211_ATTR_PMKSA_CANDIDATE);
19374 	if (!attr)
19375 		goto nla_put_failure;
19376 
19377 	if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
19378 	    nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
19379 	    (preauth &&
19380 	     nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
19381 		goto nla_put_failure;
19382 
19383 	nla_nest_end(msg, attr);
19384 
19385 	genlmsg_end(msg, hdr);
19386 
19387 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
19388 				NL80211_MCGRP_MLME, gfp);
19389 	return;
19390 
19391  nla_put_failure:
19392 	nlmsg_free(msg);
19393 }
19394 
cfg80211_pmksa_candidate_notify(struct net_device * dev,int index,const u8 * bssid,bool preauth,gfp_t gfp)19395 void cfg80211_pmksa_candidate_notify(struct net_device *dev, int index,
19396 				     const u8 *bssid, bool preauth, gfp_t gfp)
19397 {
19398 	struct wireless_dev *wdev = dev->ieee80211_ptr;
19399 	struct wiphy *wiphy = wdev->wiphy;
19400 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
19401 
19402 	trace_cfg80211_pmksa_candidate_notify(dev, index, bssid, preauth);
19403 	nl80211_pmksa_candidate_notify(rdev, dev, index, bssid, preauth, gfp);
19404 }
19405 EXPORT_SYMBOL(cfg80211_pmksa_candidate_notify);
19406 
nl80211_ch_switch_notify(struct cfg80211_registered_device * rdev,struct net_device * netdev,unsigned int link_id,struct cfg80211_chan_def * chandef,gfp_t gfp,enum nl80211_commands notif,u8 count,bool quiet,u16 punct_bitmap)19407 static void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
19408 				     struct net_device *netdev,
19409 				     unsigned int link_id,
19410 				     struct cfg80211_chan_def *chandef,
19411 				     gfp_t gfp,
19412 				     enum nl80211_commands notif,
19413 				     u8 count, bool quiet, u16 punct_bitmap)
19414 {
19415 	struct wireless_dev *wdev = netdev->ieee80211_ptr;
19416 	struct sk_buff *msg;
19417 	void *hdr;
19418 
19419 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
19420 	if (!msg)
19421 		return;
19422 
19423 	hdr = nl80211hdr_put(msg, 0, 0, 0, notif);
19424 	if (!hdr) {
19425 		nlmsg_free(msg);
19426 		return;
19427 	}
19428 
19429 	if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
19430 		goto nla_put_failure;
19431 
19432 	if (wdev->valid_links &&
19433 	    nla_put_u8(msg, NL80211_ATTR_MLO_LINK_ID, link_id))
19434 		goto nla_put_failure;
19435 
19436 	if (nl80211_send_chandef(msg, chandef))
19437 		goto nla_put_failure;
19438 
19439 	if (notif == NL80211_CMD_CH_SWITCH_STARTED_NOTIFY) {
19440 		if (nla_put_u32(msg, NL80211_ATTR_CH_SWITCH_COUNT, count))
19441 			goto nla_put_failure;
19442 		if (quiet &&
19443 		    nla_put_flag(msg, NL80211_ATTR_CH_SWITCH_BLOCK_TX))
19444 			goto nla_put_failure;
19445 	}
19446 
19447 	if (nla_put_u32(msg, NL80211_ATTR_PUNCT_BITMAP, punct_bitmap))
19448 		goto nla_put_failure;
19449 
19450 	genlmsg_end(msg, hdr);
19451 
19452 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
19453 				NL80211_MCGRP_MLME, gfp);
19454 	return;
19455 
19456  nla_put_failure:
19457 	nlmsg_free(msg);
19458 }
19459 
cfg80211_ch_switch_notify(struct net_device * dev,struct cfg80211_chan_def * chandef,unsigned int link_id,u16 punct_bitmap)19460 void cfg80211_ch_switch_notify(struct net_device *dev,
19461 			       struct cfg80211_chan_def *chandef,
19462 			       unsigned int link_id, u16 punct_bitmap)
19463 {
19464 	struct wireless_dev *wdev = dev->ieee80211_ptr;
19465 	struct wiphy *wiphy = wdev->wiphy;
19466 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
19467 
19468 	ASSERT_WDEV_LOCK(wdev);
19469 	WARN_INVALID_LINK_ID(wdev, link_id);
19470 
19471 	trace_cfg80211_ch_switch_notify(dev, chandef, link_id, punct_bitmap);
19472 
19473 	switch (wdev->iftype) {
19474 	case NL80211_IFTYPE_STATION:
19475 	case NL80211_IFTYPE_P2P_CLIENT:
19476 		if (!WARN_ON(!wdev->links[link_id].client.current_bss))
19477 			cfg80211_update_assoc_bss_entry(wdev, link_id,
19478 							chandef->chan);
19479 		break;
19480 	case NL80211_IFTYPE_MESH_POINT:
19481 		wdev->u.mesh.chandef = *chandef;
19482 		wdev->u.mesh.preset_chandef = *chandef;
19483 		break;
19484 	case NL80211_IFTYPE_AP:
19485 	case NL80211_IFTYPE_P2P_GO:
19486 		wdev->links[link_id].ap.chandef = *chandef;
19487 		break;
19488 	case NL80211_IFTYPE_ADHOC:
19489 		wdev->u.ibss.chandef = *chandef;
19490 		break;
19491 	default:
19492 		WARN_ON(1);
19493 		break;
19494 	}
19495 
19496 	cfg80211_sched_dfs_chan_update(rdev);
19497 
19498 	nl80211_ch_switch_notify(rdev, dev, link_id, chandef, GFP_KERNEL,
19499 				 NL80211_CMD_CH_SWITCH_NOTIFY, 0, false,
19500 				 punct_bitmap);
19501 }
19502 EXPORT_SYMBOL(cfg80211_ch_switch_notify);
19503 
cfg80211_ch_switch_started_notify(struct net_device * dev,struct cfg80211_chan_def * chandef,unsigned int link_id,u8 count,bool quiet,u16 punct_bitmap)19504 void cfg80211_ch_switch_started_notify(struct net_device *dev,
19505 				       struct cfg80211_chan_def *chandef,
19506 				       unsigned int link_id, u8 count,
19507 				       bool quiet, u16 punct_bitmap)
19508 {
19509 	struct wireless_dev *wdev = dev->ieee80211_ptr;
19510 	struct wiphy *wiphy = wdev->wiphy;
19511 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
19512 
19513 	ASSERT_WDEV_LOCK(wdev);
19514 	WARN_INVALID_LINK_ID(wdev, link_id);
19515 
19516 	trace_cfg80211_ch_switch_started_notify(dev, chandef, link_id,
19517 						punct_bitmap);
19518 
19519 
19520 	nl80211_ch_switch_notify(rdev, dev, link_id, chandef, GFP_KERNEL,
19521 				 NL80211_CMD_CH_SWITCH_STARTED_NOTIFY,
19522 				 count, quiet, punct_bitmap);
19523 }
19524 EXPORT_SYMBOL(cfg80211_ch_switch_started_notify);
19525 
cfg80211_bss_color_notify(struct net_device * dev,enum nl80211_commands cmd,u8 count,u64 color_bitmap)19526 int cfg80211_bss_color_notify(struct net_device *dev,
19527 			      enum nl80211_commands cmd, u8 count,
19528 			      u64 color_bitmap)
19529 {
19530 	struct wireless_dev *wdev = dev->ieee80211_ptr;
19531 	struct wiphy *wiphy = wdev->wiphy;
19532 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
19533 	struct sk_buff *msg;
19534 	void *hdr;
19535 
19536 	ASSERT_WDEV_LOCK(wdev);
19537 
19538 	trace_cfg80211_bss_color_notify(dev, cmd, count, color_bitmap);
19539 
19540 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
19541 	if (!msg)
19542 		return -ENOMEM;
19543 
19544 	hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
19545 	if (!hdr)
19546 		goto nla_put_failure;
19547 
19548 	if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
19549 		goto nla_put_failure;
19550 
19551 	if (cmd == NL80211_CMD_COLOR_CHANGE_STARTED &&
19552 	    nla_put_u32(msg, NL80211_ATTR_COLOR_CHANGE_COUNT, count))
19553 		goto nla_put_failure;
19554 
19555 	if (cmd == NL80211_CMD_OBSS_COLOR_COLLISION &&
19556 	    nla_put_u64_64bit(msg, NL80211_ATTR_OBSS_COLOR_BITMAP,
19557 			      color_bitmap, NL80211_ATTR_PAD))
19558 		goto nla_put_failure;
19559 
19560 	genlmsg_end(msg, hdr);
19561 
19562 	return genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
19563 				       msg, 0, NL80211_MCGRP_MLME, GFP_KERNEL);
19564 
19565 nla_put_failure:
19566 	nlmsg_free(msg);
19567 	return -EINVAL;
19568 }
19569 EXPORT_SYMBOL(cfg80211_bss_color_notify);
19570 
19571 void
nl80211_radar_notify(struct cfg80211_registered_device * rdev,const struct cfg80211_chan_def * chandef,enum nl80211_radar_event event,struct net_device * netdev,gfp_t gfp)19572 nl80211_radar_notify(struct cfg80211_registered_device *rdev,
19573 		     const struct cfg80211_chan_def *chandef,
19574 		     enum nl80211_radar_event event,
19575 		     struct net_device *netdev, gfp_t gfp)
19576 {
19577 	struct sk_buff *msg;
19578 	void *hdr;
19579 
19580 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
19581 	if (!msg)
19582 		return;
19583 
19584 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_RADAR_DETECT);
19585 	if (!hdr) {
19586 		nlmsg_free(msg);
19587 		return;
19588 	}
19589 
19590 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
19591 		goto nla_put_failure;
19592 
19593 	/* NOP and radar events don't need a netdev parameter */
19594 	if (netdev) {
19595 		struct wireless_dev *wdev = netdev->ieee80211_ptr;
19596 
19597 		if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
19598 		    nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
19599 				      NL80211_ATTR_PAD))
19600 			goto nla_put_failure;
19601 	}
19602 
19603 	if (nla_put_u32(msg, NL80211_ATTR_RADAR_EVENT, event))
19604 		goto nla_put_failure;
19605 
19606 	if (nl80211_send_chandef(msg, chandef))
19607 		goto nla_put_failure;
19608 
19609 	genlmsg_end(msg, hdr);
19610 
19611 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
19612 				NL80211_MCGRP_MLME, gfp);
19613 	return;
19614 
19615  nla_put_failure:
19616 	nlmsg_free(msg);
19617 }
19618 
cfg80211_sta_opmode_change_notify(struct net_device * dev,const u8 * mac,struct sta_opmode_info * sta_opmode,gfp_t gfp)19619 void cfg80211_sta_opmode_change_notify(struct net_device *dev, const u8 *mac,
19620 				       struct sta_opmode_info *sta_opmode,
19621 				       gfp_t gfp)
19622 {
19623 	struct sk_buff *msg;
19624 	struct wireless_dev *wdev = dev->ieee80211_ptr;
19625 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
19626 	void *hdr;
19627 
19628 	if (WARN_ON(!mac))
19629 		return;
19630 
19631 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
19632 	if (!msg)
19633 		return;
19634 
19635 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_STA_OPMODE_CHANGED);
19636 	if (!hdr) {
19637 		nlmsg_free(msg);
19638 		return;
19639 	}
19640 
19641 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
19642 		goto nla_put_failure;
19643 
19644 	if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
19645 		goto nla_put_failure;
19646 
19647 	if (nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac))
19648 		goto nla_put_failure;
19649 
19650 	if ((sta_opmode->changed & STA_OPMODE_SMPS_MODE_CHANGED) &&
19651 	    nla_put_u8(msg, NL80211_ATTR_SMPS_MODE, sta_opmode->smps_mode))
19652 		goto nla_put_failure;
19653 
19654 	if ((sta_opmode->changed & STA_OPMODE_MAX_BW_CHANGED) &&
19655 	    nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, sta_opmode->bw))
19656 		goto nla_put_failure;
19657 
19658 	if ((sta_opmode->changed & STA_OPMODE_N_SS_CHANGED) &&
19659 	    nla_put_u8(msg, NL80211_ATTR_NSS, sta_opmode->rx_nss))
19660 		goto nla_put_failure;
19661 
19662 	genlmsg_end(msg, hdr);
19663 
19664 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
19665 				NL80211_MCGRP_MLME, gfp);
19666 
19667 	return;
19668 
19669 nla_put_failure:
19670 	nlmsg_free(msg);
19671 }
19672 EXPORT_SYMBOL(cfg80211_sta_opmode_change_notify);
19673 
cfg80211_probe_status(struct net_device * dev,const u8 * addr,u64 cookie,bool acked,s32 ack_signal,bool is_valid_ack_signal,gfp_t gfp)19674 void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
19675 			   u64 cookie, bool acked, s32 ack_signal,
19676 			   bool is_valid_ack_signal, gfp_t gfp)
19677 {
19678 	struct wireless_dev *wdev = dev->ieee80211_ptr;
19679 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
19680 	struct sk_buff *msg;
19681 	void *hdr;
19682 
19683 	trace_cfg80211_probe_status(dev, addr, cookie, acked);
19684 
19685 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
19686 
19687 	if (!msg)
19688 		return;
19689 
19690 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
19691 	if (!hdr) {
19692 		nlmsg_free(msg);
19693 		return;
19694 	}
19695 
19696 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
19697 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
19698 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
19699 	    nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
19700 			      NL80211_ATTR_PAD) ||
19701 	    (acked && nla_put_flag(msg, NL80211_ATTR_ACK)) ||
19702 	    (is_valid_ack_signal && nla_put_s32(msg, NL80211_ATTR_ACK_SIGNAL,
19703 						ack_signal)))
19704 		goto nla_put_failure;
19705 
19706 	genlmsg_end(msg, hdr);
19707 
19708 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
19709 				NL80211_MCGRP_MLME, gfp);
19710 	return;
19711 
19712  nla_put_failure:
19713 	nlmsg_free(msg);
19714 }
19715 EXPORT_SYMBOL(cfg80211_probe_status);
19716 
cfg80211_report_obss_beacon_khz(struct wiphy * wiphy,const u8 * frame,size_t len,int freq,int sig_dbm)19717 void cfg80211_report_obss_beacon_khz(struct wiphy *wiphy, const u8 *frame,
19718 				     size_t len, int freq, int sig_dbm)
19719 {
19720 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
19721 	struct sk_buff *msg;
19722 	void *hdr;
19723 	struct cfg80211_beacon_registration *reg;
19724 
19725 	trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
19726 
19727 	spin_lock_bh(&rdev->beacon_registrations_lock);
19728 	list_for_each_entry(reg, &rdev->beacon_registrations, list) {
19729 		msg = nlmsg_new(len + 100, GFP_ATOMIC);
19730 		if (!msg) {
19731 			spin_unlock_bh(&rdev->beacon_registrations_lock);
19732 			return;
19733 		}
19734 
19735 		hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
19736 		if (!hdr)
19737 			goto nla_put_failure;
19738 
19739 		if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
19740 		    (freq &&
19741 		     (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
19742 				  KHZ_TO_MHZ(freq)) ||
19743 		      nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ_OFFSET,
19744 				  freq % 1000))) ||
19745 		    (sig_dbm &&
19746 		     nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
19747 		    nla_put(msg, NL80211_ATTR_FRAME, len, frame))
19748 			goto nla_put_failure;
19749 
19750 		genlmsg_end(msg, hdr);
19751 
19752 		genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
19753 	}
19754 	spin_unlock_bh(&rdev->beacon_registrations_lock);
19755 	return;
19756 
19757  nla_put_failure:
19758 	spin_unlock_bh(&rdev->beacon_registrations_lock);
19759 	nlmsg_free(msg);
19760 }
19761 EXPORT_SYMBOL(cfg80211_report_obss_beacon_khz);
19762 
19763 #ifdef CONFIG_PM
cfg80211_net_detect_results(struct sk_buff * msg,struct cfg80211_wowlan_wakeup * wakeup)19764 static int cfg80211_net_detect_results(struct sk_buff *msg,
19765 				       struct cfg80211_wowlan_wakeup *wakeup)
19766 {
19767 	struct cfg80211_wowlan_nd_info *nd = wakeup->net_detect;
19768 	struct nlattr *nl_results, *nl_match, *nl_freqs;
19769 	int i, j;
19770 
19771 	nl_results = nla_nest_start_noflag(msg,
19772 					   NL80211_WOWLAN_TRIG_NET_DETECT_RESULTS);
19773 	if (!nl_results)
19774 		return -EMSGSIZE;
19775 
19776 	for (i = 0; i < nd->n_matches; i++) {
19777 		struct cfg80211_wowlan_nd_match *match = nd->matches[i];
19778 
19779 		nl_match = nla_nest_start_noflag(msg, i);
19780 		if (!nl_match)
19781 			break;
19782 
19783 		/* The SSID attribute is optional in nl80211, but for
19784 		 * simplicity reasons it's always present in the
19785 		 * cfg80211 structure.  If a driver can't pass the
19786 		 * SSID, that needs to be changed.  A zero length SSID
19787 		 * is still a valid SSID (wildcard), so it cannot be
19788 		 * used for this purpose.
19789 		 */
19790 		if (nla_put(msg, NL80211_ATTR_SSID, match->ssid.ssid_len,
19791 			    match->ssid.ssid)) {
19792 			nla_nest_cancel(msg, nl_match);
19793 			goto out;
19794 		}
19795 
19796 		if (match->n_channels) {
19797 			nl_freqs = nla_nest_start_noflag(msg,
19798 							 NL80211_ATTR_SCAN_FREQUENCIES);
19799 			if (!nl_freqs) {
19800 				nla_nest_cancel(msg, nl_match);
19801 				goto out;
19802 			}
19803 
19804 			for (j = 0; j < match->n_channels; j++) {
19805 				if (nla_put_u32(msg, j, match->channels[j])) {
19806 					nla_nest_cancel(msg, nl_freqs);
19807 					nla_nest_cancel(msg, nl_match);
19808 					goto out;
19809 				}
19810 			}
19811 
19812 			nla_nest_end(msg, nl_freqs);
19813 		}
19814 
19815 		nla_nest_end(msg, nl_match);
19816 	}
19817 
19818 out:
19819 	nla_nest_end(msg, nl_results);
19820 	return 0;
19821 }
19822 
cfg80211_report_wowlan_wakeup(struct wireless_dev * wdev,struct cfg80211_wowlan_wakeup * wakeup,gfp_t gfp)19823 void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev,
19824 				   struct cfg80211_wowlan_wakeup *wakeup,
19825 				   gfp_t gfp)
19826 {
19827 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
19828 	struct sk_buff *msg;
19829 	void *hdr;
19830 	int size = 200;
19831 
19832 	trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup);
19833 
19834 	if (wakeup)
19835 		size += wakeup->packet_present_len;
19836 
19837 	msg = nlmsg_new(size, gfp);
19838 	if (!msg)
19839 		return;
19840 
19841 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN);
19842 	if (!hdr)
19843 		goto free_msg;
19844 
19845 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
19846 	    nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
19847 			      NL80211_ATTR_PAD))
19848 		goto free_msg;
19849 
19850 	if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
19851 					wdev->netdev->ifindex))
19852 		goto free_msg;
19853 
19854 	if (wakeup) {
19855 		struct nlattr *reasons;
19856 
19857 		reasons = nla_nest_start_noflag(msg,
19858 						NL80211_ATTR_WOWLAN_TRIGGERS);
19859 		if (!reasons)
19860 			goto free_msg;
19861 
19862 		if (wakeup->disconnect &&
19863 		    nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT))
19864 			goto free_msg;
19865 		if (wakeup->magic_pkt &&
19866 		    nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT))
19867 			goto free_msg;
19868 		if (wakeup->gtk_rekey_failure &&
19869 		    nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE))
19870 			goto free_msg;
19871 		if (wakeup->eap_identity_req &&
19872 		    nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST))
19873 			goto free_msg;
19874 		if (wakeup->four_way_handshake &&
19875 		    nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE))
19876 			goto free_msg;
19877 		if (wakeup->rfkill_release &&
19878 		    nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))
19879 			goto free_msg;
19880 
19881 		if (wakeup->pattern_idx >= 0 &&
19882 		    nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
19883 				wakeup->pattern_idx))
19884 			goto free_msg;
19885 
19886 		if (wakeup->tcp_match &&
19887 		    nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_MATCH))
19888 			goto free_msg;
19889 
19890 		if (wakeup->tcp_connlost &&
19891 		    nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_CONNLOST))
19892 			goto free_msg;
19893 
19894 		if (wakeup->tcp_nomoretokens &&
19895 		    nla_put_flag(msg,
19896 				 NL80211_WOWLAN_TRIG_WAKEUP_TCP_NOMORETOKENS))
19897 			goto free_msg;
19898 
19899 		if (wakeup->packet) {
19900 			u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211;
19901 			u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN;
19902 
19903 			if (!wakeup->packet_80211) {
19904 				pkt_attr =
19905 					NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023;
19906 				len_attr =
19907 					NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN;
19908 			}
19909 
19910 			if (wakeup->packet_len &&
19911 			    nla_put_u32(msg, len_attr, wakeup->packet_len))
19912 				goto free_msg;
19913 
19914 			if (nla_put(msg, pkt_attr, wakeup->packet_present_len,
19915 				    wakeup->packet))
19916 				goto free_msg;
19917 		}
19918 
19919 		if (wakeup->net_detect &&
19920 		    cfg80211_net_detect_results(msg, wakeup))
19921 				goto free_msg;
19922 
19923 		nla_nest_end(msg, reasons);
19924 	}
19925 
19926 	genlmsg_end(msg, hdr);
19927 
19928 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
19929 				NL80211_MCGRP_MLME, gfp);
19930 	return;
19931 
19932  free_msg:
19933 	nlmsg_free(msg);
19934 }
19935 EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup);
19936 #endif
19937 
cfg80211_tdls_oper_request(struct net_device * dev,const u8 * peer,enum nl80211_tdls_operation oper,u16 reason_code,gfp_t gfp)19938 void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
19939 				enum nl80211_tdls_operation oper,
19940 				u16 reason_code, gfp_t gfp)
19941 {
19942 	struct wireless_dev *wdev = dev->ieee80211_ptr;
19943 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
19944 	struct sk_buff *msg;
19945 	void *hdr;
19946 
19947 	trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
19948 					 reason_code);
19949 
19950 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
19951 	if (!msg)
19952 		return;
19953 
19954 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
19955 	if (!hdr) {
19956 		nlmsg_free(msg);
19957 		return;
19958 	}
19959 
19960 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
19961 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
19962 	    nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
19963 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
19964 	    (reason_code > 0 &&
19965 	     nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
19966 		goto nla_put_failure;
19967 
19968 	genlmsg_end(msg, hdr);
19969 
19970 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
19971 				NL80211_MCGRP_MLME, gfp);
19972 	return;
19973 
19974  nla_put_failure:
19975 	nlmsg_free(msg);
19976 }
19977 EXPORT_SYMBOL(cfg80211_tdls_oper_request);
19978 
nl80211_netlink_notify(struct notifier_block * nb,unsigned long state,void * _notify)19979 static int nl80211_netlink_notify(struct notifier_block * nb,
19980 				  unsigned long state,
19981 				  void *_notify)
19982 {
19983 	struct netlink_notify *notify = _notify;
19984 	struct cfg80211_registered_device *rdev;
19985 	struct wireless_dev *wdev;
19986 	struct cfg80211_beacon_registration *reg, *tmp;
19987 
19988 	if (state != NETLINK_URELEASE || notify->protocol != NETLINK_GENERIC)
19989 		return NOTIFY_DONE;
19990 
19991 	rcu_read_lock();
19992 
19993 	list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
19994 		struct cfg80211_sched_scan_request *sched_scan_req;
19995 
19996 		list_for_each_entry_rcu(sched_scan_req,
19997 					&rdev->sched_scan_req_list,
19998 					list) {
19999 			if (sched_scan_req->owner_nlportid == notify->portid) {
20000 				sched_scan_req->nl_owner_dead = true;
20001 				wiphy_work_queue(&rdev->wiphy,
20002 						 &rdev->sched_scan_stop_wk);
20003 			}
20004 		}
20005 
20006 		list_for_each_entry_rcu(wdev, &rdev->wiphy.wdev_list, list) {
20007 			cfg80211_mlme_unregister_socket(wdev, notify->portid);
20008 
20009 			if (wdev->owner_nlportid == notify->portid) {
20010 				wdev->nl_owner_dead = true;
20011 				schedule_work(&rdev->destroy_work);
20012 			} else if (wdev->conn_owner_nlportid == notify->portid) {
20013 				schedule_work(&wdev->disconnect_wk);
20014 			}
20015 
20016 			cfg80211_release_pmsr(wdev, notify->portid);
20017 		}
20018 
20019 		spin_lock_bh(&rdev->beacon_registrations_lock);
20020 		list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
20021 					 list) {
20022 			if (reg->nlportid == notify->portid) {
20023 				list_del(&reg->list);
20024 				kfree(reg);
20025 				break;
20026 			}
20027 		}
20028 		spin_unlock_bh(&rdev->beacon_registrations_lock);
20029 	}
20030 
20031 	rcu_read_unlock();
20032 
20033 	/*
20034 	 * It is possible that the user space process that is controlling the
20035 	 * indoor setting disappeared, so notify the regulatory core.
20036 	 */
20037 	regulatory_netlink_notify(notify->portid);
20038 	return NOTIFY_OK;
20039 }
20040 
20041 static struct notifier_block nl80211_netlink_notifier = {
20042 	.notifier_call = nl80211_netlink_notify,
20043 };
20044 
cfg80211_ft_event(struct net_device * netdev,struct cfg80211_ft_event_params * ft_event)20045 void cfg80211_ft_event(struct net_device *netdev,
20046 		       struct cfg80211_ft_event_params *ft_event)
20047 {
20048 	struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy;
20049 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
20050 	struct sk_buff *msg;
20051 	void *hdr;
20052 
20053 	trace_cfg80211_ft_event(wiphy, netdev, ft_event);
20054 
20055 	if (!ft_event->target_ap)
20056 		return;
20057 
20058 	msg = nlmsg_new(100 + ft_event->ies_len + ft_event->ric_ies_len,
20059 			GFP_KERNEL);
20060 	if (!msg)
20061 		return;
20062 
20063 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FT_EVENT);
20064 	if (!hdr)
20065 		goto out;
20066 
20067 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
20068 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
20069 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, ft_event->target_ap))
20070 		goto out;
20071 
20072 	if (ft_event->ies &&
20073 	    nla_put(msg, NL80211_ATTR_IE, ft_event->ies_len, ft_event->ies))
20074 		goto out;
20075 	if (ft_event->ric_ies &&
20076 	    nla_put(msg, NL80211_ATTR_IE_RIC, ft_event->ric_ies_len,
20077 		    ft_event->ric_ies))
20078 		goto out;
20079 
20080 	genlmsg_end(msg, hdr);
20081 
20082 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
20083 				NL80211_MCGRP_MLME, GFP_KERNEL);
20084 	return;
20085  out:
20086 	nlmsg_free(msg);
20087 }
20088 EXPORT_SYMBOL(cfg80211_ft_event);
20089 
cfg80211_crit_proto_stopped(struct wireless_dev * wdev,gfp_t gfp)20090 void cfg80211_crit_proto_stopped(struct wireless_dev *wdev, gfp_t gfp)
20091 {
20092 	struct cfg80211_registered_device *rdev;
20093 	struct sk_buff *msg;
20094 	void *hdr;
20095 	u32 nlportid;
20096 
20097 	rdev = wiphy_to_rdev(wdev->wiphy);
20098 	if (!rdev->crit_proto_nlportid)
20099 		return;
20100 
20101 	nlportid = rdev->crit_proto_nlportid;
20102 	rdev->crit_proto_nlportid = 0;
20103 
20104 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
20105 	if (!msg)
20106 		return;
20107 
20108 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CRIT_PROTOCOL_STOP);
20109 	if (!hdr)
20110 		goto nla_put_failure;
20111 
20112 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
20113 	    nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
20114 			      NL80211_ATTR_PAD))
20115 		goto nla_put_failure;
20116 
20117 	genlmsg_end(msg, hdr);
20118 
20119 	genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
20120 	return;
20121 
20122  nla_put_failure:
20123 	nlmsg_free(msg);
20124 }
20125 EXPORT_SYMBOL(cfg80211_crit_proto_stopped);
20126 
nl80211_send_ap_stopped(struct wireless_dev * wdev,unsigned int link_id)20127 void nl80211_send_ap_stopped(struct wireless_dev *wdev, unsigned int link_id)
20128 {
20129 	struct wiphy *wiphy = wdev->wiphy;
20130 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
20131 	struct sk_buff *msg;
20132 	void *hdr;
20133 
20134 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
20135 	if (!msg)
20136 		return;
20137 
20138 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_STOP_AP);
20139 	if (!hdr)
20140 		goto out;
20141 
20142 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
20143 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex) ||
20144 	    nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
20145 			      NL80211_ATTR_PAD) ||
20146 	    (wdev->valid_links &&
20147 	     nla_put_u8(msg, NL80211_ATTR_MLO_LINK_ID, link_id)))
20148 		goto out;
20149 
20150 	genlmsg_end(msg, hdr);
20151 
20152 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(wiphy), msg, 0,
20153 				NL80211_MCGRP_MLME, GFP_KERNEL);
20154 	return;
20155  out:
20156 	nlmsg_free(msg);
20157 }
20158 
cfg80211_external_auth_request(struct net_device * dev,struct cfg80211_external_auth_params * params,gfp_t gfp)20159 int cfg80211_external_auth_request(struct net_device *dev,
20160 				   struct cfg80211_external_auth_params *params,
20161 				   gfp_t gfp)
20162 {
20163 	struct wireless_dev *wdev = dev->ieee80211_ptr;
20164 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
20165 	struct sk_buff *msg;
20166 	void *hdr;
20167 
20168 	if (!wdev->conn_owner_nlportid)
20169 		return -EINVAL;
20170 
20171 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
20172 	if (!msg)
20173 		return -ENOMEM;
20174 
20175 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_EXTERNAL_AUTH);
20176 	if (!hdr)
20177 		goto nla_put_failure;
20178 
20179 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
20180 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
20181 	    nla_put_u32(msg, NL80211_ATTR_AKM_SUITES, params->key_mgmt_suite) ||
20182 	    nla_put_u32(msg, NL80211_ATTR_EXTERNAL_AUTH_ACTION,
20183 			params->action) ||
20184 	    nla_put(msg, NL80211_ATTR_BSSID, ETH_ALEN, params->bssid) ||
20185 	    nla_put(msg, NL80211_ATTR_SSID, params->ssid.ssid_len,
20186 		    params->ssid.ssid) ||
20187 	    (!is_zero_ether_addr(params->mld_addr) &&
20188 	     nla_put(msg, NL80211_ATTR_MLD_ADDR, ETH_ALEN, params->mld_addr)))
20189 		goto nla_put_failure;
20190 
20191 	genlmsg_end(msg, hdr);
20192 	genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
20193 			wdev->conn_owner_nlportid);
20194 	return 0;
20195 
20196  nla_put_failure:
20197 	nlmsg_free(msg);
20198 	return -ENOBUFS;
20199 }
20200 EXPORT_SYMBOL(cfg80211_external_auth_request);
20201 
cfg80211_update_owe_info_event(struct net_device * netdev,struct cfg80211_update_owe_info * owe_info,gfp_t gfp)20202 void cfg80211_update_owe_info_event(struct net_device *netdev,
20203 				    struct cfg80211_update_owe_info *owe_info,
20204 				    gfp_t gfp)
20205 {
20206 	struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy;
20207 	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
20208 	struct sk_buff *msg;
20209 	void *hdr;
20210 
20211 	trace_cfg80211_update_owe_info_event(wiphy, netdev, owe_info);
20212 
20213 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
20214 	if (!msg)
20215 		return;
20216 
20217 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_UPDATE_OWE_INFO);
20218 	if (!hdr)
20219 		goto nla_put_failure;
20220 
20221 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
20222 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
20223 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, owe_info->peer))
20224 		goto nla_put_failure;
20225 
20226 	if (!owe_info->ie_len ||
20227 	    nla_put(msg, NL80211_ATTR_IE, owe_info->ie_len, owe_info->ie))
20228 		goto nla_put_failure;
20229 
20230 	if (owe_info->assoc_link_id != -1) {
20231 		if (nla_put_u8(msg, NL80211_ATTR_MLO_LINK_ID,
20232 			       owe_info->assoc_link_id))
20233 			goto nla_put_failure;
20234 
20235 		if (!is_zero_ether_addr(owe_info->peer_mld_addr) &&
20236 		    nla_put(msg, NL80211_ATTR_MLD_ADDR, ETH_ALEN,
20237 			    owe_info->peer_mld_addr))
20238 			goto nla_put_failure;
20239 	}
20240 
20241 	genlmsg_end(msg, hdr);
20242 
20243 	genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
20244 				NL80211_MCGRP_MLME, gfp);
20245 	return;
20246 
20247 nla_put_failure:
20248 	genlmsg_cancel(msg, hdr);
20249 	nlmsg_free(msg);
20250 }
20251 EXPORT_SYMBOL(cfg80211_update_owe_info_event);
20252 
20253 /* initialisation/exit functions */
20254 
nl80211_init(void)20255 int __init nl80211_init(void)
20256 {
20257 	int err;
20258 
20259 	err = genl_register_family(&nl80211_fam);
20260 	if (err)
20261 		return err;
20262 
20263 	err = netlink_register_notifier(&nl80211_netlink_notifier);
20264 	if (err)
20265 		goto err_out;
20266 
20267 	return 0;
20268  err_out:
20269 	genl_unregister_family(&nl80211_fam);
20270 	return err;
20271 }
20272 
nl80211_exit(void)20273 void nl80211_exit(void)
20274 {
20275 	netlink_unregister_notifier(&nl80211_netlink_notifier);
20276 	genl_unregister_family(&nl80211_fam);
20277 }
20278