1 /* 2 * This is the new netlink-based wireless configuration interface. 3 * 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net> 5 * Copyright 2013-2014 Intel Mobile Communications GmbH 6 * Copyright 2015-2016 Intel Deutschland GmbH 7 */ 8 9 #include <linux/if.h> 10 #include <linux/module.h> 11 #include <linux/err.h> 12 #include <linux/slab.h> 13 #include <linux/list.h> 14 #include <linux/if_ether.h> 15 #include <linux/ieee80211.h> 16 #include <linux/nl80211.h> 17 #include <linux/rtnetlink.h> 18 #include <linux/netlink.h> 19 #include <linux/etherdevice.h> 20 #include <net/net_namespace.h> 21 #include <net/genetlink.h> 22 #include <net/cfg80211.h> 23 #include <net/sock.h> 24 #include <net/inet_connection_sock.h> 25 #include "core.h" 26 #include "nl80211.h" 27 #include "reg.h" 28 #include "rdev-ops.h" 29 30 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev, 31 struct genl_info *info, 32 struct cfg80211_crypto_settings *settings, 33 int cipher_limit); 34 35 /* the netlink family */ 36 static struct genl_family nl80211_fam; 37 38 /* multicast groups */ 39 enum nl80211_multicast_groups { 40 NL80211_MCGRP_CONFIG, 41 NL80211_MCGRP_SCAN, 42 NL80211_MCGRP_REGULATORY, 43 NL80211_MCGRP_MLME, 44 NL80211_MCGRP_VENDOR, 45 NL80211_MCGRP_NAN, 46 NL80211_MCGRP_TESTMODE /* keep last - ifdef! */ 47 }; 48 49 static const struct genl_multicast_group nl80211_mcgrps[] = { 50 [NL80211_MCGRP_CONFIG] = { .name = NL80211_MULTICAST_GROUP_CONFIG }, 51 [NL80211_MCGRP_SCAN] = { .name = NL80211_MULTICAST_GROUP_SCAN }, 52 [NL80211_MCGRP_REGULATORY] = { .name = NL80211_MULTICAST_GROUP_REG }, 53 [NL80211_MCGRP_MLME] = { .name = NL80211_MULTICAST_GROUP_MLME }, 54 [NL80211_MCGRP_VENDOR] = { .name = NL80211_MULTICAST_GROUP_VENDOR }, 55 [NL80211_MCGRP_NAN] = { .name = NL80211_MULTICAST_GROUP_NAN }, 56 #ifdef CONFIG_NL80211_TESTMODE 57 [NL80211_MCGRP_TESTMODE] = { .name = NL80211_MULTICAST_GROUP_TESTMODE } 58 #endif 59 }; 60 61 /* returns ERR_PTR values */ 62 static struct wireless_dev * 63 __cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs) 64 { 65 struct cfg80211_registered_device *rdev; 66 struct wireless_dev *result = NULL; 67 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX]; 68 bool have_wdev_id = attrs[NL80211_ATTR_WDEV]; 69 u64 wdev_id; 70 int wiphy_idx = -1; 71 int ifidx = -1; 72 73 ASSERT_RTNL(); 74 75 if (!have_ifidx && !have_wdev_id) 76 return ERR_PTR(-EINVAL); 77 78 if (have_ifidx) 79 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]); 80 if (have_wdev_id) { 81 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]); 82 wiphy_idx = wdev_id >> 32; 83 } 84 85 list_for_each_entry(rdev, &cfg80211_rdev_list, list) { 86 struct wireless_dev *wdev; 87 88 if (wiphy_net(&rdev->wiphy) != netns) 89 continue; 90 91 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx) 92 continue; 93 94 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) { 95 if (have_ifidx && wdev->netdev && 96 wdev->netdev->ifindex == ifidx) { 97 result = wdev; 98 break; 99 } 100 if (have_wdev_id && wdev->identifier == (u32)wdev_id) { 101 result = wdev; 102 break; 103 } 104 } 105 106 if (result) 107 break; 108 } 109 110 if (result) 111 return result; 112 return ERR_PTR(-ENODEV); 113 } 114 115 static struct cfg80211_registered_device * 116 __cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs) 117 { 118 struct cfg80211_registered_device *rdev = NULL, *tmp; 119 struct net_device *netdev; 120 121 ASSERT_RTNL(); 122 123 if (!attrs[NL80211_ATTR_WIPHY] && 124 !attrs[NL80211_ATTR_IFINDEX] && 125 !attrs[NL80211_ATTR_WDEV]) 126 return ERR_PTR(-EINVAL); 127 128 if (attrs[NL80211_ATTR_WIPHY]) 129 rdev = cfg80211_rdev_by_wiphy_idx( 130 nla_get_u32(attrs[NL80211_ATTR_WIPHY])); 131 132 if (attrs[NL80211_ATTR_WDEV]) { 133 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]); 134 struct wireless_dev *wdev; 135 bool found = false; 136 137 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32); 138 if (tmp) { 139 /* make sure wdev exists */ 140 list_for_each_entry(wdev, &tmp->wiphy.wdev_list, list) { 141 if (wdev->identifier != (u32)wdev_id) 142 continue; 143 found = true; 144 break; 145 } 146 147 if (!found) 148 tmp = NULL; 149 150 if (rdev && tmp != rdev) 151 return ERR_PTR(-EINVAL); 152 rdev = tmp; 153 } 154 } 155 156 if (attrs[NL80211_ATTR_IFINDEX]) { 157 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]); 158 159 netdev = __dev_get_by_index(netns, ifindex); 160 if (netdev) { 161 if (netdev->ieee80211_ptr) 162 tmp = wiphy_to_rdev( 163 netdev->ieee80211_ptr->wiphy); 164 else 165 tmp = NULL; 166 167 /* not wireless device -- return error */ 168 if (!tmp) 169 return ERR_PTR(-EINVAL); 170 171 /* mismatch -- return error */ 172 if (rdev && tmp != rdev) 173 return ERR_PTR(-EINVAL); 174 175 rdev = tmp; 176 } 177 } 178 179 if (!rdev) 180 return ERR_PTR(-ENODEV); 181 182 if (netns != wiphy_net(&rdev->wiphy)) 183 return ERR_PTR(-ENODEV); 184 185 return rdev; 186 } 187 188 /* 189 * This function returns a pointer to the driver 190 * that the genl_info item that is passed refers to. 191 * 192 * The result of this can be a PTR_ERR and hence must 193 * be checked with IS_ERR() for errors. 194 */ 195 static struct cfg80211_registered_device * 196 cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info) 197 { 198 return __cfg80211_rdev_from_attrs(netns, info->attrs); 199 } 200 201 /* policy for the attributes */ 202 static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = { 203 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 }, 204 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING, 205 .len = 20-1 }, 206 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED }, 207 208 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 }, 209 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 }, 210 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 }, 211 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 }, 212 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 }, 213 214 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 }, 215 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 }, 216 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 }, 217 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 }, 218 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 }, 219 [NL80211_ATTR_WIPHY_DYN_ACK] = { .type = NLA_FLAG }, 220 221 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 }, 222 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 }, 223 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 }, 224 225 [NL80211_ATTR_MAC] = { .len = ETH_ALEN }, 226 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN }, 227 228 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, }, 229 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY, 230 .len = WLAN_MAX_KEY_LEN }, 231 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 }, 232 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 }, 233 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG }, 234 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 }, 235 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 }, 236 237 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 }, 238 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 }, 239 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY, 240 .len = IEEE80211_MAX_DATA_LEN }, 241 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY, 242 .len = IEEE80211_MAX_DATA_LEN }, 243 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 }, 244 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED }, 245 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 }, 246 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY, 247 .len = NL80211_MAX_SUPP_RATES }, 248 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 }, 249 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 }, 250 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ }, 251 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY, 252 .len = IEEE80211_MAX_MESH_ID_LEN }, 253 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 }, 254 255 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 }, 256 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED }, 257 258 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 }, 259 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 }, 260 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 }, 261 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY, 262 .len = NL80211_MAX_SUPP_RATES }, 263 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 }, 264 265 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED }, 266 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG }, 267 268 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN }, 269 270 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 }, 271 [NL80211_ATTR_IE] = { .type = NLA_BINARY, 272 .len = IEEE80211_MAX_DATA_LEN }, 273 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED }, 274 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED }, 275 276 [NL80211_ATTR_SSID] = { .type = NLA_BINARY, 277 .len = IEEE80211_MAX_SSID_LEN }, 278 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 }, 279 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 }, 280 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG }, 281 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG }, 282 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 }, 283 [NL80211_ATTR_STA_FLAGS2] = { 284 .len = sizeof(struct nl80211_sta_flag_update), 285 }, 286 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG }, 287 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 }, 288 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG }, 289 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG }, 290 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 }, 291 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 }, 292 [NL80211_ATTR_PID] = { .type = NLA_U32 }, 293 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 }, 294 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY, 295 .len = WLAN_PMKID_LEN }, 296 [NL80211_ATTR_DURATION] = { .type = NLA_U32 }, 297 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 }, 298 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED }, 299 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY, 300 .len = IEEE80211_MAX_DATA_LEN }, 301 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, }, 302 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 }, 303 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, }, 304 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG }, 305 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 }, 306 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 }, 307 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 }, 308 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 }, 309 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 }, 310 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 }, 311 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 }, 312 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG }, 313 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED }, 314 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED }, 315 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 }, 316 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 }, 317 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED }, 318 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED }, 319 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 }, 320 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY, 321 .len = IEEE80211_MAX_DATA_LEN }, 322 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY, 323 .len = IEEE80211_MAX_DATA_LEN }, 324 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG }, 325 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED }, 326 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG }, 327 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 }, 328 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 }, 329 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 }, 330 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG }, 331 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG }, 332 [NL80211_ATTR_TDLS_INITIATOR] = { .type = NLA_FLAG }, 333 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG }, 334 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY, 335 .len = IEEE80211_MAX_DATA_LEN }, 336 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 }, 337 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG }, 338 [NL80211_ATTR_HT_CAPABILITY_MASK] = { 339 .len = NL80211_HT_CAPABILITY_LEN 340 }, 341 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 }, 342 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 }, 343 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 }, 344 [NL80211_ATTR_WDEV] = { .type = NLA_U64 }, 345 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 }, 346 [NL80211_ATTR_AUTH_DATA] = { .type = NLA_BINARY, }, 347 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN }, 348 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 }, 349 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 }, 350 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 }, 351 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 }, 352 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED }, 353 [NL80211_ATTR_STA_CAPABILITY] = { .type = NLA_U16 }, 354 [NL80211_ATTR_STA_EXT_CAPABILITY] = { .type = NLA_BINARY, }, 355 [NL80211_ATTR_SPLIT_WIPHY_DUMP] = { .type = NLA_FLAG, }, 356 [NL80211_ATTR_DISABLE_VHT] = { .type = NLA_FLAG }, 357 [NL80211_ATTR_VHT_CAPABILITY_MASK] = { 358 .len = NL80211_VHT_CAPABILITY_LEN, 359 }, 360 [NL80211_ATTR_MDID] = { .type = NLA_U16 }, 361 [NL80211_ATTR_IE_RIC] = { .type = NLA_BINARY, 362 .len = IEEE80211_MAX_DATA_LEN }, 363 [NL80211_ATTR_PEER_AID] = { .type = NLA_U16 }, 364 [NL80211_ATTR_CH_SWITCH_COUNT] = { .type = NLA_U32 }, 365 [NL80211_ATTR_CH_SWITCH_BLOCK_TX] = { .type = NLA_FLAG }, 366 [NL80211_ATTR_CSA_IES] = { .type = NLA_NESTED }, 367 [NL80211_ATTR_CSA_C_OFF_BEACON] = { .type = NLA_BINARY }, 368 [NL80211_ATTR_CSA_C_OFF_PRESP] = { .type = NLA_BINARY }, 369 [NL80211_ATTR_STA_SUPPORTED_CHANNELS] = { .type = NLA_BINARY }, 370 [NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES] = { .type = NLA_BINARY }, 371 [NL80211_ATTR_HANDLE_DFS] = { .type = NLA_FLAG }, 372 [NL80211_ATTR_OPMODE_NOTIF] = { .type = NLA_U8 }, 373 [NL80211_ATTR_VENDOR_ID] = { .type = NLA_U32 }, 374 [NL80211_ATTR_VENDOR_SUBCMD] = { .type = NLA_U32 }, 375 [NL80211_ATTR_VENDOR_DATA] = { .type = NLA_BINARY }, 376 [NL80211_ATTR_QOS_MAP] = { .type = NLA_BINARY, 377 .len = IEEE80211_QOS_MAP_LEN_MAX }, 378 [NL80211_ATTR_MAC_HINT] = { .len = ETH_ALEN }, 379 [NL80211_ATTR_WIPHY_FREQ_HINT] = { .type = NLA_U32 }, 380 [NL80211_ATTR_TDLS_PEER_CAPABILITY] = { .type = NLA_U32 }, 381 [NL80211_ATTR_SOCKET_OWNER] = { .type = NLA_FLAG }, 382 [NL80211_ATTR_CSA_C_OFFSETS_TX] = { .type = NLA_BINARY }, 383 [NL80211_ATTR_USE_RRM] = { .type = NLA_FLAG }, 384 [NL80211_ATTR_TSID] = { .type = NLA_U8 }, 385 [NL80211_ATTR_USER_PRIO] = { .type = NLA_U8 }, 386 [NL80211_ATTR_ADMITTED_TIME] = { .type = NLA_U16 }, 387 [NL80211_ATTR_SMPS_MODE] = { .type = NLA_U8 }, 388 [NL80211_ATTR_MAC_MASK] = { .len = ETH_ALEN }, 389 [NL80211_ATTR_WIPHY_SELF_MANAGED_REG] = { .type = NLA_FLAG }, 390 [NL80211_ATTR_NETNS_FD] = { .type = NLA_U32 }, 391 [NL80211_ATTR_SCHED_SCAN_DELAY] = { .type = NLA_U32 }, 392 [NL80211_ATTR_REG_INDOOR] = { .type = NLA_FLAG }, 393 [NL80211_ATTR_PBSS] = { .type = NLA_FLAG }, 394 [NL80211_ATTR_BSS_SELECT] = { .type = NLA_NESTED }, 395 [NL80211_ATTR_STA_SUPPORT_P2P_PS] = { .type = NLA_U8 }, 396 [NL80211_ATTR_MU_MIMO_GROUP_DATA] = { 397 .len = VHT_MUMIMO_GROUPS_DATA_LEN 398 }, 399 [NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR] = { .len = ETH_ALEN }, 400 [NL80211_ATTR_NAN_MASTER_PREF] = { .type = NLA_U8 }, 401 [NL80211_ATTR_NAN_DUAL] = { .type = NLA_U8 }, 402 [NL80211_ATTR_NAN_FUNC] = { .type = NLA_NESTED }, 403 [NL80211_ATTR_FILS_KEK] = { .type = NLA_BINARY, 404 .len = FILS_MAX_KEK_LEN }, 405 [NL80211_ATTR_FILS_NONCES] = { .len = 2 * FILS_NONCE_LEN }, 406 [NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED] = { .type = NLA_FLAG, }, 407 [NL80211_ATTR_BSSID] = { .len = ETH_ALEN }, 408 }; 409 410 /* policy for the key attributes */ 411 static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = { 412 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN }, 413 [NL80211_KEY_IDX] = { .type = NLA_U8 }, 414 [NL80211_KEY_CIPHER] = { .type = NLA_U32 }, 415 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 }, 416 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG }, 417 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG }, 418 [NL80211_KEY_TYPE] = { .type = NLA_U32 }, 419 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED }, 420 }; 421 422 /* policy for the key default flags */ 423 static const struct nla_policy 424 nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = { 425 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG }, 426 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG }, 427 }; 428 429 #ifdef CONFIG_PM 430 /* policy for WoWLAN attributes */ 431 static const struct nla_policy 432 nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = { 433 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG }, 434 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG }, 435 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG }, 436 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED }, 437 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG }, 438 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG }, 439 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG }, 440 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG }, 441 [NL80211_WOWLAN_TRIG_TCP_CONNECTION] = { .type = NLA_NESTED }, 442 [NL80211_WOWLAN_TRIG_NET_DETECT] = { .type = NLA_NESTED }, 443 }; 444 445 static const struct nla_policy 446 nl80211_wowlan_tcp_policy[NUM_NL80211_WOWLAN_TCP] = { 447 [NL80211_WOWLAN_TCP_SRC_IPV4] = { .type = NLA_U32 }, 448 [NL80211_WOWLAN_TCP_DST_IPV4] = { .type = NLA_U32 }, 449 [NL80211_WOWLAN_TCP_DST_MAC] = { .len = ETH_ALEN }, 450 [NL80211_WOWLAN_TCP_SRC_PORT] = { .type = NLA_U16 }, 451 [NL80211_WOWLAN_TCP_DST_PORT] = { .type = NLA_U16 }, 452 [NL80211_WOWLAN_TCP_DATA_PAYLOAD] = { .len = 1 }, 453 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ] = { 454 .len = sizeof(struct nl80211_wowlan_tcp_data_seq) 455 }, 456 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN] = { 457 .len = sizeof(struct nl80211_wowlan_tcp_data_token) 458 }, 459 [NL80211_WOWLAN_TCP_DATA_INTERVAL] = { .type = NLA_U32 }, 460 [NL80211_WOWLAN_TCP_WAKE_PAYLOAD] = { .len = 1 }, 461 [NL80211_WOWLAN_TCP_WAKE_MASK] = { .len = 1 }, 462 }; 463 #endif /* CONFIG_PM */ 464 465 /* policy for coalesce rule attributes */ 466 static const struct nla_policy 467 nl80211_coalesce_policy[NUM_NL80211_ATTR_COALESCE_RULE] = { 468 [NL80211_ATTR_COALESCE_RULE_DELAY] = { .type = NLA_U32 }, 469 [NL80211_ATTR_COALESCE_RULE_CONDITION] = { .type = NLA_U32 }, 470 [NL80211_ATTR_COALESCE_RULE_PKT_PATTERN] = { .type = NLA_NESTED }, 471 }; 472 473 /* policy for GTK rekey offload attributes */ 474 static const struct nla_policy 475 nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = { 476 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN }, 477 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN }, 478 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN }, 479 }; 480 481 static const struct nla_policy 482 nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = { 483 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY, 484 .len = IEEE80211_MAX_SSID_LEN }, 485 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 }, 486 }; 487 488 static const struct nla_policy 489 nl80211_plan_policy[NL80211_SCHED_SCAN_PLAN_MAX + 1] = { 490 [NL80211_SCHED_SCAN_PLAN_INTERVAL] = { .type = NLA_U32 }, 491 [NL80211_SCHED_SCAN_PLAN_ITERATIONS] = { .type = NLA_U32 }, 492 }; 493 494 static const struct nla_policy 495 nl80211_bss_select_policy[NL80211_BSS_SELECT_ATTR_MAX + 1] = { 496 [NL80211_BSS_SELECT_ATTR_RSSI] = { .type = NLA_FLAG }, 497 [NL80211_BSS_SELECT_ATTR_BAND_PREF] = { .type = NLA_U32 }, 498 [NL80211_BSS_SELECT_ATTR_RSSI_ADJUST] = { 499 .len = sizeof(struct nl80211_bss_select_rssi_adjust) 500 }, 501 }; 502 503 /* policy for NAN function attributes */ 504 static const struct nla_policy 505 nl80211_nan_func_policy[NL80211_NAN_FUNC_ATTR_MAX + 1] = { 506 [NL80211_NAN_FUNC_TYPE] = { .type = NLA_U8 }, 507 [NL80211_NAN_FUNC_SERVICE_ID] = { .type = NLA_BINARY, 508 .len = NL80211_NAN_FUNC_SERVICE_ID_LEN }, 509 [NL80211_NAN_FUNC_PUBLISH_TYPE] = { .type = NLA_U8 }, 510 [NL80211_NAN_FUNC_PUBLISH_BCAST] = { .type = NLA_FLAG }, 511 [NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE] = { .type = NLA_FLAG }, 512 [NL80211_NAN_FUNC_FOLLOW_UP_ID] = { .type = NLA_U8 }, 513 [NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID] = { .type = NLA_U8 }, 514 [NL80211_NAN_FUNC_FOLLOW_UP_DEST] = { .len = ETH_ALEN }, 515 [NL80211_NAN_FUNC_CLOSE_RANGE] = { .type = NLA_FLAG }, 516 [NL80211_NAN_FUNC_TTL] = { .type = NLA_U32 }, 517 [NL80211_NAN_FUNC_SERVICE_INFO] = { .type = NLA_BINARY, 518 .len = NL80211_NAN_FUNC_SERVICE_SPEC_INFO_MAX_LEN }, 519 [NL80211_NAN_FUNC_SRF] = { .type = NLA_NESTED }, 520 [NL80211_NAN_FUNC_RX_MATCH_FILTER] = { .type = NLA_NESTED }, 521 [NL80211_NAN_FUNC_TX_MATCH_FILTER] = { .type = NLA_NESTED }, 522 [NL80211_NAN_FUNC_INSTANCE_ID] = { .type = NLA_U8 }, 523 [NL80211_NAN_FUNC_TERM_REASON] = { .type = NLA_U8 }, 524 }; 525 526 /* policy for Service Response Filter attributes */ 527 static const struct nla_policy 528 nl80211_nan_srf_policy[NL80211_NAN_SRF_ATTR_MAX + 1] = { 529 [NL80211_NAN_SRF_INCLUDE] = { .type = NLA_FLAG }, 530 [NL80211_NAN_SRF_BF] = { .type = NLA_BINARY, 531 .len = NL80211_NAN_FUNC_SRF_MAX_LEN }, 532 [NL80211_NAN_SRF_BF_IDX] = { .type = NLA_U8 }, 533 [NL80211_NAN_SRF_MAC_ADDRS] = { .type = NLA_NESTED }, 534 }; 535 536 static int nl80211_prepare_wdev_dump(struct sk_buff *skb, 537 struct netlink_callback *cb, 538 struct cfg80211_registered_device **rdev, 539 struct wireless_dev **wdev) 540 { 541 int err; 542 543 rtnl_lock(); 544 545 if (!cb->args[0]) { 546 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, 547 genl_family_attrbuf(&nl80211_fam), 548 nl80211_fam.maxattr, nl80211_policy); 549 if (err) 550 goto out_unlock; 551 552 *wdev = __cfg80211_wdev_from_attrs( 553 sock_net(skb->sk), 554 genl_family_attrbuf(&nl80211_fam)); 555 if (IS_ERR(*wdev)) { 556 err = PTR_ERR(*wdev); 557 goto out_unlock; 558 } 559 *rdev = wiphy_to_rdev((*wdev)->wiphy); 560 /* 0 is the first index - add 1 to parse only once */ 561 cb->args[0] = (*rdev)->wiphy_idx + 1; 562 cb->args[1] = (*wdev)->identifier; 563 } else { 564 /* subtract the 1 again here */ 565 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1); 566 struct wireless_dev *tmp; 567 568 if (!wiphy) { 569 err = -ENODEV; 570 goto out_unlock; 571 } 572 *rdev = wiphy_to_rdev(wiphy); 573 *wdev = NULL; 574 575 list_for_each_entry(tmp, &(*rdev)->wiphy.wdev_list, list) { 576 if (tmp->identifier == cb->args[1]) { 577 *wdev = tmp; 578 break; 579 } 580 } 581 582 if (!*wdev) { 583 err = -ENODEV; 584 goto out_unlock; 585 } 586 } 587 588 return 0; 589 out_unlock: 590 rtnl_unlock(); 591 return err; 592 } 593 594 static void nl80211_finish_wdev_dump(struct cfg80211_registered_device *rdev) 595 { 596 rtnl_unlock(); 597 } 598 599 /* IE validation */ 600 static bool is_valid_ie_attr(const struct nlattr *attr) 601 { 602 const u8 *pos; 603 int len; 604 605 if (!attr) 606 return true; 607 608 pos = nla_data(attr); 609 len = nla_len(attr); 610 611 while (len) { 612 u8 elemlen; 613 614 if (len < 2) 615 return false; 616 len -= 2; 617 618 elemlen = pos[1]; 619 if (elemlen > len) 620 return false; 621 622 len -= elemlen; 623 pos += 2 + elemlen; 624 } 625 626 return true; 627 } 628 629 /* message building helper */ 630 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq, 631 int flags, u8 cmd) 632 { 633 /* since there is no private header just add the generic one */ 634 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd); 635 } 636 637 static int nl80211_msg_put_channel(struct sk_buff *msg, 638 struct ieee80211_channel *chan, 639 bool large) 640 { 641 /* Some channels must be completely excluded from the 642 * list to protect old user-space tools from breaking 643 */ 644 if (!large && chan->flags & 645 (IEEE80211_CHAN_NO_10MHZ | IEEE80211_CHAN_NO_20MHZ)) 646 return 0; 647 648 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ, 649 chan->center_freq)) 650 goto nla_put_failure; 651 652 if ((chan->flags & IEEE80211_CHAN_DISABLED) && 653 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED)) 654 goto nla_put_failure; 655 if (chan->flags & IEEE80211_CHAN_NO_IR) { 656 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IR)) 657 goto nla_put_failure; 658 if (nla_put_flag(msg, __NL80211_FREQUENCY_ATTR_NO_IBSS)) 659 goto nla_put_failure; 660 } 661 if (chan->flags & IEEE80211_CHAN_RADAR) { 662 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR)) 663 goto nla_put_failure; 664 if (large) { 665 u32 time; 666 667 time = elapsed_jiffies_msecs(chan->dfs_state_entered); 668 669 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_STATE, 670 chan->dfs_state)) 671 goto nla_put_failure; 672 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_TIME, 673 time)) 674 goto nla_put_failure; 675 if (nla_put_u32(msg, 676 NL80211_FREQUENCY_ATTR_DFS_CAC_TIME, 677 chan->dfs_cac_ms)) 678 goto nla_put_failure; 679 } 680 } 681 682 if (large) { 683 if ((chan->flags & IEEE80211_CHAN_NO_HT40MINUS) && 684 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_MINUS)) 685 goto nla_put_failure; 686 if ((chan->flags & IEEE80211_CHAN_NO_HT40PLUS) && 687 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_PLUS)) 688 goto nla_put_failure; 689 if ((chan->flags & IEEE80211_CHAN_NO_80MHZ) && 690 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_80MHZ)) 691 goto nla_put_failure; 692 if ((chan->flags & IEEE80211_CHAN_NO_160MHZ) && 693 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_160MHZ)) 694 goto nla_put_failure; 695 if ((chan->flags & IEEE80211_CHAN_INDOOR_ONLY) && 696 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_INDOOR_ONLY)) 697 goto nla_put_failure; 698 if ((chan->flags & IEEE80211_CHAN_IR_CONCURRENT) && 699 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_IR_CONCURRENT)) 700 goto nla_put_failure; 701 if ((chan->flags & IEEE80211_CHAN_NO_20MHZ) && 702 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_20MHZ)) 703 goto nla_put_failure; 704 if ((chan->flags & IEEE80211_CHAN_NO_10MHZ) && 705 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_10MHZ)) 706 goto nla_put_failure; 707 } 708 709 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER, 710 DBM_TO_MBM(chan->max_power))) 711 goto nla_put_failure; 712 713 return 0; 714 715 nla_put_failure: 716 return -ENOBUFS; 717 } 718 719 /* netlink command implementations */ 720 721 struct key_parse { 722 struct key_params p; 723 int idx; 724 int type; 725 bool def, defmgmt; 726 bool def_uni, def_multi; 727 }; 728 729 static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k) 730 { 731 struct nlattr *tb[NL80211_KEY_MAX + 1]; 732 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key, 733 nl80211_key_policy); 734 if (err) 735 return err; 736 737 k->def = !!tb[NL80211_KEY_DEFAULT]; 738 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT]; 739 740 if (k->def) { 741 k->def_uni = true; 742 k->def_multi = true; 743 } 744 if (k->defmgmt) 745 k->def_multi = true; 746 747 if (tb[NL80211_KEY_IDX]) 748 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]); 749 750 if (tb[NL80211_KEY_DATA]) { 751 k->p.key = nla_data(tb[NL80211_KEY_DATA]); 752 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]); 753 } 754 755 if (tb[NL80211_KEY_SEQ]) { 756 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]); 757 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]); 758 } 759 760 if (tb[NL80211_KEY_CIPHER]) 761 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]); 762 763 if (tb[NL80211_KEY_TYPE]) { 764 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]); 765 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES) 766 return -EINVAL; 767 } 768 769 if (tb[NL80211_KEY_DEFAULT_TYPES]) { 770 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES]; 771 772 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1, 773 tb[NL80211_KEY_DEFAULT_TYPES], 774 nl80211_key_default_policy); 775 if (err) 776 return err; 777 778 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST]; 779 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST]; 780 } 781 782 return 0; 783 } 784 785 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k) 786 { 787 if (info->attrs[NL80211_ATTR_KEY_DATA]) { 788 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]); 789 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]); 790 } 791 792 if (info->attrs[NL80211_ATTR_KEY_SEQ]) { 793 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]); 794 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]); 795 } 796 797 if (info->attrs[NL80211_ATTR_KEY_IDX]) 798 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]); 799 800 if (info->attrs[NL80211_ATTR_KEY_CIPHER]) 801 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]); 802 803 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT]; 804 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT]; 805 806 if (k->def) { 807 k->def_uni = true; 808 k->def_multi = true; 809 } 810 if (k->defmgmt) 811 k->def_multi = true; 812 813 if (info->attrs[NL80211_ATTR_KEY_TYPE]) { 814 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]); 815 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES) 816 return -EINVAL; 817 } 818 819 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) { 820 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES]; 821 int err = nla_parse_nested( 822 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1, 823 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES], 824 nl80211_key_default_policy); 825 if (err) 826 return err; 827 828 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST]; 829 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST]; 830 } 831 832 return 0; 833 } 834 835 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k) 836 { 837 int err; 838 839 memset(k, 0, sizeof(*k)); 840 k->idx = -1; 841 k->type = -1; 842 843 if (info->attrs[NL80211_ATTR_KEY]) 844 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k); 845 else 846 err = nl80211_parse_key_old(info, k); 847 848 if (err) 849 return err; 850 851 if (k->def && k->defmgmt) 852 return -EINVAL; 853 854 if (k->defmgmt) { 855 if (k->def_uni || !k->def_multi) 856 return -EINVAL; 857 } 858 859 if (k->idx != -1) { 860 if (k->defmgmt) { 861 if (k->idx < 4 || k->idx > 5) 862 return -EINVAL; 863 } else if (k->def) { 864 if (k->idx < 0 || k->idx > 3) 865 return -EINVAL; 866 } else { 867 if (k->idx < 0 || k->idx > 5) 868 return -EINVAL; 869 } 870 } 871 872 return 0; 873 } 874 875 static struct cfg80211_cached_keys * 876 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev, 877 struct nlattr *keys, bool *no_ht) 878 { 879 struct key_parse parse; 880 struct nlattr *key; 881 struct cfg80211_cached_keys *result; 882 int rem, err, def = 0; 883 bool have_key = false; 884 885 nla_for_each_nested(key, keys, rem) { 886 have_key = true; 887 break; 888 } 889 890 if (!have_key) 891 return NULL; 892 893 result = kzalloc(sizeof(*result), GFP_KERNEL); 894 if (!result) 895 return ERR_PTR(-ENOMEM); 896 897 result->def = -1; 898 899 nla_for_each_nested(key, keys, rem) { 900 memset(&parse, 0, sizeof(parse)); 901 parse.idx = -1; 902 903 err = nl80211_parse_key_new(key, &parse); 904 if (err) 905 goto error; 906 err = -EINVAL; 907 if (!parse.p.key) 908 goto error; 909 if (parse.idx < 0 || parse.idx > 3) 910 goto error; 911 if (parse.def) { 912 if (def) 913 goto error; 914 def = 1; 915 result->def = parse.idx; 916 if (!parse.def_uni || !parse.def_multi) 917 goto error; 918 } else if (parse.defmgmt) 919 goto error; 920 err = cfg80211_validate_key_settings(rdev, &parse.p, 921 parse.idx, false, NULL); 922 if (err) 923 goto error; 924 if (parse.p.cipher != WLAN_CIPHER_SUITE_WEP40 && 925 parse.p.cipher != WLAN_CIPHER_SUITE_WEP104) { 926 err = -EINVAL; 927 goto error; 928 } 929 result->params[parse.idx].cipher = parse.p.cipher; 930 result->params[parse.idx].key_len = parse.p.key_len; 931 result->params[parse.idx].key = result->data[parse.idx]; 932 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len); 933 934 /* must be WEP key if we got here */ 935 if (no_ht) 936 *no_ht = true; 937 } 938 939 if (result->def < 0) { 940 err = -EINVAL; 941 goto error; 942 } 943 944 return result; 945 error: 946 kfree(result); 947 return ERR_PTR(err); 948 } 949 950 static int nl80211_key_allowed(struct wireless_dev *wdev) 951 { 952 ASSERT_WDEV_LOCK(wdev); 953 954 switch (wdev->iftype) { 955 case NL80211_IFTYPE_AP: 956 case NL80211_IFTYPE_AP_VLAN: 957 case NL80211_IFTYPE_P2P_GO: 958 case NL80211_IFTYPE_MESH_POINT: 959 break; 960 case NL80211_IFTYPE_ADHOC: 961 case NL80211_IFTYPE_STATION: 962 case NL80211_IFTYPE_P2P_CLIENT: 963 if (!wdev->current_bss) 964 return -ENOLINK; 965 break; 966 case NL80211_IFTYPE_UNSPECIFIED: 967 case NL80211_IFTYPE_OCB: 968 case NL80211_IFTYPE_MONITOR: 969 case NL80211_IFTYPE_NAN: 970 case NL80211_IFTYPE_P2P_DEVICE: 971 case NL80211_IFTYPE_WDS: 972 case NUM_NL80211_IFTYPES: 973 return -EINVAL; 974 } 975 976 return 0; 977 } 978 979 static struct ieee80211_channel *nl80211_get_valid_chan(struct wiphy *wiphy, 980 struct nlattr *tb) 981 { 982 struct ieee80211_channel *chan; 983 984 if (tb == NULL) 985 return NULL; 986 chan = ieee80211_get_channel(wiphy, nla_get_u32(tb)); 987 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) 988 return NULL; 989 return chan; 990 } 991 992 static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes) 993 { 994 struct nlattr *nl_modes = nla_nest_start(msg, attr); 995 int i; 996 997 if (!nl_modes) 998 goto nla_put_failure; 999 1000 i = 0; 1001 while (ifmodes) { 1002 if ((ifmodes & 1) && nla_put_flag(msg, i)) 1003 goto nla_put_failure; 1004 ifmodes >>= 1; 1005 i++; 1006 } 1007 1008 nla_nest_end(msg, nl_modes); 1009 return 0; 1010 1011 nla_put_failure: 1012 return -ENOBUFS; 1013 } 1014 1015 static int nl80211_put_iface_combinations(struct wiphy *wiphy, 1016 struct sk_buff *msg, 1017 bool large) 1018 { 1019 struct nlattr *nl_combis; 1020 int i, j; 1021 1022 nl_combis = nla_nest_start(msg, 1023 NL80211_ATTR_INTERFACE_COMBINATIONS); 1024 if (!nl_combis) 1025 goto nla_put_failure; 1026 1027 for (i = 0; i < wiphy->n_iface_combinations; i++) { 1028 const struct ieee80211_iface_combination *c; 1029 struct nlattr *nl_combi, *nl_limits; 1030 1031 c = &wiphy->iface_combinations[i]; 1032 1033 nl_combi = nla_nest_start(msg, i + 1); 1034 if (!nl_combi) 1035 goto nla_put_failure; 1036 1037 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS); 1038 if (!nl_limits) 1039 goto nla_put_failure; 1040 1041 for (j = 0; j < c->n_limits; j++) { 1042 struct nlattr *nl_limit; 1043 1044 nl_limit = nla_nest_start(msg, j + 1); 1045 if (!nl_limit) 1046 goto nla_put_failure; 1047 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX, 1048 c->limits[j].max)) 1049 goto nla_put_failure; 1050 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES, 1051 c->limits[j].types)) 1052 goto nla_put_failure; 1053 nla_nest_end(msg, nl_limit); 1054 } 1055 1056 nla_nest_end(msg, nl_limits); 1057 1058 if (c->beacon_int_infra_match && 1059 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH)) 1060 goto nla_put_failure; 1061 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS, 1062 c->num_different_channels) || 1063 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM, 1064 c->max_interfaces)) 1065 goto nla_put_failure; 1066 if (large && 1067 (nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS, 1068 c->radar_detect_widths) || 1069 nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_REGIONS, 1070 c->radar_detect_regions))) 1071 goto nla_put_failure; 1072 if (c->beacon_int_min_gcd && 1073 nla_put_u32(msg, NL80211_IFACE_COMB_BI_MIN_GCD, 1074 c->beacon_int_min_gcd)) 1075 goto nla_put_failure; 1076 1077 nla_nest_end(msg, nl_combi); 1078 } 1079 1080 nla_nest_end(msg, nl_combis); 1081 1082 return 0; 1083 nla_put_failure: 1084 return -ENOBUFS; 1085 } 1086 1087 #ifdef CONFIG_PM 1088 static int nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device *rdev, 1089 struct sk_buff *msg) 1090 { 1091 const struct wiphy_wowlan_tcp_support *tcp = rdev->wiphy.wowlan->tcp; 1092 struct nlattr *nl_tcp; 1093 1094 if (!tcp) 1095 return 0; 1096 1097 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION); 1098 if (!nl_tcp) 1099 return -ENOBUFS; 1100 1101 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD, 1102 tcp->data_payload_max)) 1103 return -ENOBUFS; 1104 1105 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD, 1106 tcp->data_payload_max)) 1107 return -ENOBUFS; 1108 1109 if (tcp->seq && nla_put_flag(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ)) 1110 return -ENOBUFS; 1111 1112 if (tcp->tok && nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN, 1113 sizeof(*tcp->tok), tcp->tok)) 1114 return -ENOBUFS; 1115 1116 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL, 1117 tcp->data_interval_max)) 1118 return -ENOBUFS; 1119 1120 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD, 1121 tcp->wake_payload_max)) 1122 return -ENOBUFS; 1123 1124 nla_nest_end(msg, nl_tcp); 1125 return 0; 1126 } 1127 1128 static int nl80211_send_wowlan(struct sk_buff *msg, 1129 struct cfg80211_registered_device *rdev, 1130 bool large) 1131 { 1132 struct nlattr *nl_wowlan; 1133 1134 if (!rdev->wiphy.wowlan) 1135 return 0; 1136 1137 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED); 1138 if (!nl_wowlan) 1139 return -ENOBUFS; 1140 1141 if (((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_ANY) && 1142 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) || 1143 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_DISCONNECT) && 1144 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) || 1145 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT) && 1146 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) || 1147 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) && 1148 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) || 1149 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) && 1150 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) || 1151 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) && 1152 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) || 1153 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) && 1154 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) || 1155 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE) && 1156 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))) 1157 return -ENOBUFS; 1158 1159 if (rdev->wiphy.wowlan->n_patterns) { 1160 struct nl80211_pattern_support pat = { 1161 .max_patterns = rdev->wiphy.wowlan->n_patterns, 1162 .min_pattern_len = rdev->wiphy.wowlan->pattern_min_len, 1163 .max_pattern_len = rdev->wiphy.wowlan->pattern_max_len, 1164 .max_pkt_offset = rdev->wiphy.wowlan->max_pkt_offset, 1165 }; 1166 1167 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN, 1168 sizeof(pat), &pat)) 1169 return -ENOBUFS; 1170 } 1171 1172 if ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_NET_DETECT) && 1173 nla_put_u32(msg, NL80211_WOWLAN_TRIG_NET_DETECT, 1174 rdev->wiphy.wowlan->max_nd_match_sets)) 1175 return -ENOBUFS; 1176 1177 if (large && nl80211_send_wowlan_tcp_caps(rdev, msg)) 1178 return -ENOBUFS; 1179 1180 nla_nest_end(msg, nl_wowlan); 1181 1182 return 0; 1183 } 1184 #endif 1185 1186 static int nl80211_send_coalesce(struct sk_buff *msg, 1187 struct cfg80211_registered_device *rdev) 1188 { 1189 struct nl80211_coalesce_rule_support rule; 1190 1191 if (!rdev->wiphy.coalesce) 1192 return 0; 1193 1194 rule.max_rules = rdev->wiphy.coalesce->n_rules; 1195 rule.max_delay = rdev->wiphy.coalesce->max_delay; 1196 rule.pat.max_patterns = rdev->wiphy.coalesce->n_patterns; 1197 rule.pat.min_pattern_len = rdev->wiphy.coalesce->pattern_min_len; 1198 rule.pat.max_pattern_len = rdev->wiphy.coalesce->pattern_max_len; 1199 rule.pat.max_pkt_offset = rdev->wiphy.coalesce->max_pkt_offset; 1200 1201 if (nla_put(msg, NL80211_ATTR_COALESCE_RULE, sizeof(rule), &rule)) 1202 return -ENOBUFS; 1203 1204 return 0; 1205 } 1206 1207 static int nl80211_send_band_rateinfo(struct sk_buff *msg, 1208 struct ieee80211_supported_band *sband) 1209 { 1210 struct nlattr *nl_rates, *nl_rate; 1211 struct ieee80211_rate *rate; 1212 int i; 1213 1214 /* add HT info */ 1215 if (sband->ht_cap.ht_supported && 1216 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET, 1217 sizeof(sband->ht_cap.mcs), 1218 &sband->ht_cap.mcs) || 1219 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA, 1220 sband->ht_cap.cap) || 1221 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR, 1222 sband->ht_cap.ampdu_factor) || 1223 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY, 1224 sband->ht_cap.ampdu_density))) 1225 return -ENOBUFS; 1226 1227 /* add VHT info */ 1228 if (sband->vht_cap.vht_supported && 1229 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET, 1230 sizeof(sband->vht_cap.vht_mcs), 1231 &sband->vht_cap.vht_mcs) || 1232 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA, 1233 sband->vht_cap.cap))) 1234 return -ENOBUFS; 1235 1236 /* add bitrates */ 1237 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES); 1238 if (!nl_rates) 1239 return -ENOBUFS; 1240 1241 for (i = 0; i < sband->n_bitrates; i++) { 1242 nl_rate = nla_nest_start(msg, i); 1243 if (!nl_rate) 1244 return -ENOBUFS; 1245 1246 rate = &sband->bitrates[i]; 1247 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE, 1248 rate->bitrate)) 1249 return -ENOBUFS; 1250 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) && 1251 nla_put_flag(msg, 1252 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE)) 1253 return -ENOBUFS; 1254 1255 nla_nest_end(msg, nl_rate); 1256 } 1257 1258 nla_nest_end(msg, nl_rates); 1259 1260 return 0; 1261 } 1262 1263 static int 1264 nl80211_send_mgmt_stypes(struct sk_buff *msg, 1265 const struct ieee80211_txrx_stypes *mgmt_stypes) 1266 { 1267 u16 stypes; 1268 struct nlattr *nl_ftypes, *nl_ifs; 1269 enum nl80211_iftype ift; 1270 int i; 1271 1272 if (!mgmt_stypes) 1273 return 0; 1274 1275 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES); 1276 if (!nl_ifs) 1277 return -ENOBUFS; 1278 1279 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) { 1280 nl_ftypes = nla_nest_start(msg, ift); 1281 if (!nl_ftypes) 1282 return -ENOBUFS; 1283 i = 0; 1284 stypes = mgmt_stypes[ift].tx; 1285 while (stypes) { 1286 if ((stypes & 1) && 1287 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE, 1288 (i << 4) | IEEE80211_FTYPE_MGMT)) 1289 return -ENOBUFS; 1290 stypes >>= 1; 1291 i++; 1292 } 1293 nla_nest_end(msg, nl_ftypes); 1294 } 1295 1296 nla_nest_end(msg, nl_ifs); 1297 1298 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES); 1299 if (!nl_ifs) 1300 return -ENOBUFS; 1301 1302 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) { 1303 nl_ftypes = nla_nest_start(msg, ift); 1304 if (!nl_ftypes) 1305 return -ENOBUFS; 1306 i = 0; 1307 stypes = mgmt_stypes[ift].rx; 1308 while (stypes) { 1309 if ((stypes & 1) && 1310 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE, 1311 (i << 4) | IEEE80211_FTYPE_MGMT)) 1312 return -ENOBUFS; 1313 stypes >>= 1; 1314 i++; 1315 } 1316 nla_nest_end(msg, nl_ftypes); 1317 } 1318 nla_nest_end(msg, nl_ifs); 1319 1320 return 0; 1321 } 1322 1323 #define CMD(op, n) \ 1324 do { \ 1325 if (rdev->ops->op) { \ 1326 i++; \ 1327 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \ 1328 goto nla_put_failure; \ 1329 } \ 1330 } while (0) 1331 1332 static int nl80211_add_commands_unsplit(struct cfg80211_registered_device *rdev, 1333 struct sk_buff *msg) 1334 { 1335 int i = 0; 1336 1337 /* 1338 * do *NOT* add anything into this function, new things need to be 1339 * advertised only to new versions of userspace that can deal with 1340 * the split (and they can't possibly care about new features... 1341 */ 1342 CMD(add_virtual_intf, NEW_INTERFACE); 1343 CMD(change_virtual_intf, SET_INTERFACE); 1344 CMD(add_key, NEW_KEY); 1345 CMD(start_ap, START_AP); 1346 CMD(add_station, NEW_STATION); 1347 CMD(add_mpath, NEW_MPATH); 1348 CMD(update_mesh_config, SET_MESH_CONFIG); 1349 CMD(change_bss, SET_BSS); 1350 CMD(auth, AUTHENTICATE); 1351 CMD(assoc, ASSOCIATE); 1352 CMD(deauth, DEAUTHENTICATE); 1353 CMD(disassoc, DISASSOCIATE); 1354 CMD(join_ibss, JOIN_IBSS); 1355 CMD(join_mesh, JOIN_MESH); 1356 CMD(set_pmksa, SET_PMKSA); 1357 CMD(del_pmksa, DEL_PMKSA); 1358 CMD(flush_pmksa, FLUSH_PMKSA); 1359 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) 1360 CMD(remain_on_channel, REMAIN_ON_CHANNEL); 1361 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK); 1362 CMD(mgmt_tx, FRAME); 1363 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL); 1364 if (rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK) { 1365 i++; 1366 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS)) 1367 goto nla_put_failure; 1368 } 1369 if (rdev->ops->set_monitor_channel || rdev->ops->start_ap || 1370 rdev->ops->join_mesh) { 1371 i++; 1372 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL)) 1373 goto nla_put_failure; 1374 } 1375 CMD(set_wds_peer, SET_WDS_PEER); 1376 if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) { 1377 CMD(tdls_mgmt, TDLS_MGMT); 1378 CMD(tdls_oper, TDLS_OPER); 1379 } 1380 if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) 1381 CMD(sched_scan_start, START_SCHED_SCAN); 1382 CMD(probe_client, PROBE_CLIENT); 1383 CMD(set_noack_map, SET_NOACK_MAP); 1384 if (rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) { 1385 i++; 1386 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS)) 1387 goto nla_put_failure; 1388 } 1389 CMD(start_p2p_device, START_P2P_DEVICE); 1390 CMD(set_mcast_rate, SET_MCAST_RATE); 1391 #ifdef CONFIG_NL80211_TESTMODE 1392 CMD(testmode_cmd, TESTMODE); 1393 #endif 1394 1395 if (rdev->ops->connect || rdev->ops->auth) { 1396 i++; 1397 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT)) 1398 goto nla_put_failure; 1399 } 1400 1401 if (rdev->ops->disconnect || rdev->ops->deauth) { 1402 i++; 1403 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT)) 1404 goto nla_put_failure; 1405 } 1406 1407 return i; 1408 nla_put_failure: 1409 return -ENOBUFS; 1410 } 1411 1412 struct nl80211_dump_wiphy_state { 1413 s64 filter_wiphy; 1414 long start; 1415 long split_start, band_start, chan_start, capa_start; 1416 bool split; 1417 }; 1418 1419 static int nl80211_send_wiphy(struct cfg80211_registered_device *rdev, 1420 enum nl80211_commands cmd, 1421 struct sk_buff *msg, u32 portid, u32 seq, 1422 int flags, struct nl80211_dump_wiphy_state *state) 1423 { 1424 void *hdr; 1425 struct nlattr *nl_bands, *nl_band; 1426 struct nlattr *nl_freqs, *nl_freq; 1427 struct nlattr *nl_cmds; 1428 enum nl80211_band band; 1429 struct ieee80211_channel *chan; 1430 int i; 1431 const struct ieee80211_txrx_stypes *mgmt_stypes = 1432 rdev->wiphy.mgmt_stypes; 1433 u32 features; 1434 1435 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 1436 if (!hdr) 1437 return -ENOBUFS; 1438 1439 if (WARN_ON(!state)) 1440 return -EINVAL; 1441 1442 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 1443 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME, 1444 wiphy_name(&rdev->wiphy)) || 1445 nla_put_u32(msg, NL80211_ATTR_GENERATION, 1446 cfg80211_rdev_list_generation)) 1447 goto nla_put_failure; 1448 1449 if (cmd != NL80211_CMD_NEW_WIPHY) 1450 goto finish; 1451 1452 switch (state->split_start) { 1453 case 0: 1454 if (nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT, 1455 rdev->wiphy.retry_short) || 1456 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG, 1457 rdev->wiphy.retry_long) || 1458 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD, 1459 rdev->wiphy.frag_threshold) || 1460 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD, 1461 rdev->wiphy.rts_threshold) || 1462 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS, 1463 rdev->wiphy.coverage_class) || 1464 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS, 1465 rdev->wiphy.max_scan_ssids) || 1466 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS, 1467 rdev->wiphy.max_sched_scan_ssids) || 1468 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN, 1469 rdev->wiphy.max_scan_ie_len) || 1470 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN, 1471 rdev->wiphy.max_sched_scan_ie_len) || 1472 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS, 1473 rdev->wiphy.max_match_sets) || 1474 nla_put_u32(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_PLANS, 1475 rdev->wiphy.max_sched_scan_plans) || 1476 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_INTERVAL, 1477 rdev->wiphy.max_sched_scan_plan_interval) || 1478 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_ITERATIONS, 1479 rdev->wiphy.max_sched_scan_plan_iterations)) 1480 goto nla_put_failure; 1481 1482 if ((rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) && 1483 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN)) 1484 goto nla_put_failure; 1485 if ((rdev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) && 1486 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH)) 1487 goto nla_put_failure; 1488 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) && 1489 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD)) 1490 goto nla_put_failure; 1491 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) && 1492 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT)) 1493 goto nla_put_failure; 1494 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) && 1495 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT)) 1496 goto nla_put_failure; 1497 if ((rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) && 1498 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP)) 1499 goto nla_put_failure; 1500 state->split_start++; 1501 if (state->split) 1502 break; 1503 case 1: 1504 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES, 1505 sizeof(u32) * rdev->wiphy.n_cipher_suites, 1506 rdev->wiphy.cipher_suites)) 1507 goto nla_put_failure; 1508 1509 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS, 1510 rdev->wiphy.max_num_pmkids)) 1511 goto nla_put_failure; 1512 1513 if ((rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) && 1514 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE)) 1515 goto nla_put_failure; 1516 1517 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX, 1518 rdev->wiphy.available_antennas_tx) || 1519 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX, 1520 rdev->wiphy.available_antennas_rx)) 1521 goto nla_put_failure; 1522 1523 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) && 1524 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD, 1525 rdev->wiphy.probe_resp_offload)) 1526 goto nla_put_failure; 1527 1528 if ((rdev->wiphy.available_antennas_tx || 1529 rdev->wiphy.available_antennas_rx) && 1530 rdev->ops->get_antenna) { 1531 u32 tx_ant = 0, rx_ant = 0; 1532 int res; 1533 1534 res = rdev_get_antenna(rdev, &tx_ant, &rx_ant); 1535 if (!res) { 1536 if (nla_put_u32(msg, 1537 NL80211_ATTR_WIPHY_ANTENNA_TX, 1538 tx_ant) || 1539 nla_put_u32(msg, 1540 NL80211_ATTR_WIPHY_ANTENNA_RX, 1541 rx_ant)) 1542 goto nla_put_failure; 1543 } 1544 } 1545 1546 state->split_start++; 1547 if (state->split) 1548 break; 1549 case 2: 1550 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES, 1551 rdev->wiphy.interface_modes)) 1552 goto nla_put_failure; 1553 state->split_start++; 1554 if (state->split) 1555 break; 1556 case 3: 1557 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS); 1558 if (!nl_bands) 1559 goto nla_put_failure; 1560 1561 for (band = state->band_start; 1562 band < NUM_NL80211_BANDS; band++) { 1563 struct ieee80211_supported_band *sband; 1564 1565 sband = rdev->wiphy.bands[band]; 1566 1567 if (!sband) 1568 continue; 1569 1570 nl_band = nla_nest_start(msg, band); 1571 if (!nl_band) 1572 goto nla_put_failure; 1573 1574 switch (state->chan_start) { 1575 case 0: 1576 if (nl80211_send_band_rateinfo(msg, sband)) 1577 goto nla_put_failure; 1578 state->chan_start++; 1579 if (state->split) 1580 break; 1581 default: 1582 /* add frequencies */ 1583 nl_freqs = nla_nest_start( 1584 msg, NL80211_BAND_ATTR_FREQS); 1585 if (!nl_freqs) 1586 goto nla_put_failure; 1587 1588 for (i = state->chan_start - 1; 1589 i < sband->n_channels; 1590 i++) { 1591 nl_freq = nla_nest_start(msg, i); 1592 if (!nl_freq) 1593 goto nla_put_failure; 1594 1595 chan = &sband->channels[i]; 1596 1597 if (nl80211_msg_put_channel( 1598 msg, chan, 1599 state->split)) 1600 goto nla_put_failure; 1601 1602 nla_nest_end(msg, nl_freq); 1603 if (state->split) 1604 break; 1605 } 1606 if (i < sband->n_channels) 1607 state->chan_start = i + 2; 1608 else 1609 state->chan_start = 0; 1610 nla_nest_end(msg, nl_freqs); 1611 } 1612 1613 nla_nest_end(msg, nl_band); 1614 1615 if (state->split) { 1616 /* start again here */ 1617 if (state->chan_start) 1618 band--; 1619 break; 1620 } 1621 } 1622 nla_nest_end(msg, nl_bands); 1623 1624 if (band < NUM_NL80211_BANDS) 1625 state->band_start = band + 1; 1626 else 1627 state->band_start = 0; 1628 1629 /* if bands & channels are done, continue outside */ 1630 if (state->band_start == 0 && state->chan_start == 0) 1631 state->split_start++; 1632 if (state->split) 1633 break; 1634 case 4: 1635 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS); 1636 if (!nl_cmds) 1637 goto nla_put_failure; 1638 1639 i = nl80211_add_commands_unsplit(rdev, msg); 1640 if (i < 0) 1641 goto nla_put_failure; 1642 if (state->split) { 1643 CMD(crit_proto_start, CRIT_PROTOCOL_START); 1644 CMD(crit_proto_stop, CRIT_PROTOCOL_STOP); 1645 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH) 1646 CMD(channel_switch, CHANNEL_SWITCH); 1647 CMD(set_qos_map, SET_QOS_MAP); 1648 if (rdev->wiphy.features & 1649 NL80211_FEATURE_SUPPORTS_WMM_ADMISSION) 1650 CMD(add_tx_ts, ADD_TX_TS); 1651 CMD(set_multicast_to_unicast, SET_MULTICAST_TO_UNICAST); 1652 CMD(update_connect_params, UPDATE_CONNECT_PARAMS); 1653 } 1654 #undef CMD 1655 1656 nla_nest_end(msg, nl_cmds); 1657 state->split_start++; 1658 if (state->split) 1659 break; 1660 case 5: 1661 if (rdev->ops->remain_on_channel && 1662 (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) && 1663 nla_put_u32(msg, 1664 NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION, 1665 rdev->wiphy.max_remain_on_channel_duration)) 1666 goto nla_put_failure; 1667 1668 if ((rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) && 1669 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK)) 1670 goto nla_put_failure; 1671 1672 if (nl80211_send_mgmt_stypes(msg, mgmt_stypes)) 1673 goto nla_put_failure; 1674 state->split_start++; 1675 if (state->split) 1676 break; 1677 case 6: 1678 #ifdef CONFIG_PM 1679 if (nl80211_send_wowlan(msg, rdev, state->split)) 1680 goto nla_put_failure; 1681 state->split_start++; 1682 if (state->split) 1683 break; 1684 #else 1685 state->split_start++; 1686 #endif 1687 case 7: 1688 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES, 1689 rdev->wiphy.software_iftypes)) 1690 goto nla_put_failure; 1691 1692 if (nl80211_put_iface_combinations(&rdev->wiphy, msg, 1693 state->split)) 1694 goto nla_put_failure; 1695 1696 state->split_start++; 1697 if (state->split) 1698 break; 1699 case 8: 1700 if ((rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) && 1701 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME, 1702 rdev->wiphy.ap_sme_capa)) 1703 goto nla_put_failure; 1704 1705 features = rdev->wiphy.features; 1706 /* 1707 * We can only add the per-channel limit information if the 1708 * dump is split, otherwise it makes it too big. Therefore 1709 * only advertise it in that case. 1710 */ 1711 if (state->split) 1712 features |= NL80211_FEATURE_ADVERTISE_CHAN_LIMITS; 1713 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS, features)) 1714 goto nla_put_failure; 1715 1716 if (rdev->wiphy.ht_capa_mod_mask && 1717 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK, 1718 sizeof(*rdev->wiphy.ht_capa_mod_mask), 1719 rdev->wiphy.ht_capa_mod_mask)) 1720 goto nla_put_failure; 1721 1722 if (rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME && 1723 rdev->wiphy.max_acl_mac_addrs && 1724 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX, 1725 rdev->wiphy.max_acl_mac_addrs)) 1726 goto nla_put_failure; 1727 1728 /* 1729 * Any information below this point is only available to 1730 * applications that can deal with it being split. This 1731 * helps ensure that newly added capabilities don't break 1732 * older tools by overrunning their buffers. 1733 * 1734 * We still increment split_start so that in the split 1735 * case we'll continue with more data in the next round, 1736 * but break unconditionally so unsplit data stops here. 1737 */ 1738 state->split_start++; 1739 break; 1740 case 9: 1741 if (rdev->wiphy.extended_capabilities && 1742 (nla_put(msg, NL80211_ATTR_EXT_CAPA, 1743 rdev->wiphy.extended_capabilities_len, 1744 rdev->wiphy.extended_capabilities) || 1745 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK, 1746 rdev->wiphy.extended_capabilities_len, 1747 rdev->wiphy.extended_capabilities_mask))) 1748 goto nla_put_failure; 1749 1750 if (rdev->wiphy.vht_capa_mod_mask && 1751 nla_put(msg, NL80211_ATTR_VHT_CAPABILITY_MASK, 1752 sizeof(*rdev->wiphy.vht_capa_mod_mask), 1753 rdev->wiphy.vht_capa_mod_mask)) 1754 goto nla_put_failure; 1755 1756 state->split_start++; 1757 break; 1758 case 10: 1759 if (nl80211_send_coalesce(msg, rdev)) 1760 goto nla_put_failure; 1761 1762 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ) && 1763 (nla_put_flag(msg, NL80211_ATTR_SUPPORT_5_MHZ) || 1764 nla_put_flag(msg, NL80211_ATTR_SUPPORT_10_MHZ))) 1765 goto nla_put_failure; 1766 1767 if (rdev->wiphy.max_ap_assoc_sta && 1768 nla_put_u32(msg, NL80211_ATTR_MAX_AP_ASSOC_STA, 1769 rdev->wiphy.max_ap_assoc_sta)) 1770 goto nla_put_failure; 1771 1772 state->split_start++; 1773 break; 1774 case 11: 1775 if (rdev->wiphy.n_vendor_commands) { 1776 const struct nl80211_vendor_cmd_info *info; 1777 struct nlattr *nested; 1778 1779 nested = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA); 1780 if (!nested) 1781 goto nla_put_failure; 1782 1783 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) { 1784 info = &rdev->wiphy.vendor_commands[i].info; 1785 if (nla_put(msg, i + 1, sizeof(*info), info)) 1786 goto nla_put_failure; 1787 } 1788 nla_nest_end(msg, nested); 1789 } 1790 1791 if (rdev->wiphy.n_vendor_events) { 1792 const struct nl80211_vendor_cmd_info *info; 1793 struct nlattr *nested; 1794 1795 nested = nla_nest_start(msg, 1796 NL80211_ATTR_VENDOR_EVENTS); 1797 if (!nested) 1798 goto nla_put_failure; 1799 1800 for (i = 0; i < rdev->wiphy.n_vendor_events; i++) { 1801 info = &rdev->wiphy.vendor_events[i]; 1802 if (nla_put(msg, i + 1, sizeof(*info), info)) 1803 goto nla_put_failure; 1804 } 1805 nla_nest_end(msg, nested); 1806 } 1807 state->split_start++; 1808 break; 1809 case 12: 1810 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH && 1811 nla_put_u8(msg, NL80211_ATTR_MAX_CSA_COUNTERS, 1812 rdev->wiphy.max_num_csa_counters)) 1813 goto nla_put_failure; 1814 1815 if (rdev->wiphy.regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED && 1816 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG)) 1817 goto nla_put_failure; 1818 1819 if (nla_put(msg, NL80211_ATTR_EXT_FEATURES, 1820 sizeof(rdev->wiphy.ext_features), 1821 rdev->wiphy.ext_features)) 1822 goto nla_put_failure; 1823 1824 if (rdev->wiphy.bss_select_support) { 1825 struct nlattr *nested; 1826 u32 bss_select_support = rdev->wiphy.bss_select_support; 1827 1828 nested = nla_nest_start(msg, NL80211_ATTR_BSS_SELECT); 1829 if (!nested) 1830 goto nla_put_failure; 1831 1832 i = 0; 1833 while (bss_select_support) { 1834 if ((bss_select_support & 1) && 1835 nla_put_flag(msg, i)) 1836 goto nla_put_failure; 1837 i++; 1838 bss_select_support >>= 1; 1839 } 1840 nla_nest_end(msg, nested); 1841 } 1842 1843 state->split_start++; 1844 break; 1845 case 13: 1846 if (rdev->wiphy.num_iftype_ext_capab && 1847 rdev->wiphy.iftype_ext_capab) { 1848 struct nlattr *nested_ext_capab, *nested; 1849 1850 nested = nla_nest_start(msg, 1851 NL80211_ATTR_IFTYPE_EXT_CAPA); 1852 if (!nested) 1853 goto nla_put_failure; 1854 1855 for (i = state->capa_start; 1856 i < rdev->wiphy.num_iftype_ext_capab; i++) { 1857 const struct wiphy_iftype_ext_capab *capab; 1858 1859 capab = &rdev->wiphy.iftype_ext_capab[i]; 1860 1861 nested_ext_capab = nla_nest_start(msg, i); 1862 if (!nested_ext_capab || 1863 nla_put_u32(msg, NL80211_ATTR_IFTYPE, 1864 capab->iftype) || 1865 nla_put(msg, NL80211_ATTR_EXT_CAPA, 1866 capab->extended_capabilities_len, 1867 capab->extended_capabilities) || 1868 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK, 1869 capab->extended_capabilities_len, 1870 capab->extended_capabilities_mask)) 1871 goto nla_put_failure; 1872 1873 nla_nest_end(msg, nested_ext_capab); 1874 if (state->split) 1875 break; 1876 } 1877 nla_nest_end(msg, nested); 1878 if (i < rdev->wiphy.num_iftype_ext_capab) { 1879 state->capa_start = i + 1; 1880 break; 1881 } 1882 } 1883 1884 /* done */ 1885 state->split_start = 0; 1886 break; 1887 } 1888 finish: 1889 genlmsg_end(msg, hdr); 1890 return 0; 1891 1892 nla_put_failure: 1893 genlmsg_cancel(msg, hdr); 1894 return -EMSGSIZE; 1895 } 1896 1897 static int nl80211_dump_wiphy_parse(struct sk_buff *skb, 1898 struct netlink_callback *cb, 1899 struct nl80211_dump_wiphy_state *state) 1900 { 1901 struct nlattr **tb = genl_family_attrbuf(&nl80211_fam); 1902 int ret = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, 1903 tb, nl80211_fam.maxattr, nl80211_policy); 1904 /* ignore parse errors for backward compatibility */ 1905 if (ret) 1906 return 0; 1907 1908 state->split = tb[NL80211_ATTR_SPLIT_WIPHY_DUMP]; 1909 if (tb[NL80211_ATTR_WIPHY]) 1910 state->filter_wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]); 1911 if (tb[NL80211_ATTR_WDEV]) 1912 state->filter_wiphy = nla_get_u64(tb[NL80211_ATTR_WDEV]) >> 32; 1913 if (tb[NL80211_ATTR_IFINDEX]) { 1914 struct net_device *netdev; 1915 struct cfg80211_registered_device *rdev; 1916 int ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]); 1917 1918 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx); 1919 if (!netdev) 1920 return -ENODEV; 1921 if (netdev->ieee80211_ptr) { 1922 rdev = wiphy_to_rdev( 1923 netdev->ieee80211_ptr->wiphy); 1924 state->filter_wiphy = rdev->wiphy_idx; 1925 } 1926 } 1927 1928 return 0; 1929 } 1930 1931 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb) 1932 { 1933 int idx = 0, ret; 1934 struct nl80211_dump_wiphy_state *state = (void *)cb->args[0]; 1935 struct cfg80211_registered_device *rdev; 1936 1937 rtnl_lock(); 1938 if (!state) { 1939 state = kzalloc(sizeof(*state), GFP_KERNEL); 1940 if (!state) { 1941 rtnl_unlock(); 1942 return -ENOMEM; 1943 } 1944 state->filter_wiphy = -1; 1945 ret = nl80211_dump_wiphy_parse(skb, cb, state); 1946 if (ret) { 1947 kfree(state); 1948 rtnl_unlock(); 1949 return ret; 1950 } 1951 cb->args[0] = (long)state; 1952 } 1953 1954 list_for_each_entry(rdev, &cfg80211_rdev_list, list) { 1955 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk))) 1956 continue; 1957 if (++idx <= state->start) 1958 continue; 1959 if (state->filter_wiphy != -1 && 1960 state->filter_wiphy != rdev->wiphy_idx) 1961 continue; 1962 /* attempt to fit multiple wiphy data chunks into the skb */ 1963 do { 1964 ret = nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY, 1965 skb, 1966 NETLINK_CB(cb->skb).portid, 1967 cb->nlh->nlmsg_seq, 1968 NLM_F_MULTI, state); 1969 if (ret < 0) { 1970 /* 1971 * If sending the wiphy data didn't fit (ENOBUFS 1972 * or EMSGSIZE returned), this SKB is still 1973 * empty (so it's not too big because another 1974 * wiphy dataset is already in the skb) and 1975 * we've not tried to adjust the dump allocation 1976 * yet ... then adjust the alloc size to be 1977 * bigger, and return 1 but with the empty skb. 1978 * This results in an empty message being RX'ed 1979 * in userspace, but that is ignored. 1980 * 1981 * We can then retry with the larger buffer. 1982 */ 1983 if ((ret == -ENOBUFS || ret == -EMSGSIZE) && 1984 !skb->len && !state->split && 1985 cb->min_dump_alloc < 4096) { 1986 cb->min_dump_alloc = 4096; 1987 state->split_start = 0; 1988 rtnl_unlock(); 1989 return 1; 1990 } 1991 idx--; 1992 break; 1993 } 1994 } while (state->split_start > 0); 1995 break; 1996 } 1997 rtnl_unlock(); 1998 1999 state->start = idx; 2000 2001 return skb->len; 2002 } 2003 2004 static int nl80211_dump_wiphy_done(struct netlink_callback *cb) 2005 { 2006 kfree((void *)cb->args[0]); 2007 return 0; 2008 } 2009 2010 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info) 2011 { 2012 struct sk_buff *msg; 2013 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2014 struct nl80211_dump_wiphy_state state = {}; 2015 2016 msg = nlmsg_new(4096, GFP_KERNEL); 2017 if (!msg) 2018 return -ENOMEM; 2019 2020 if (nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY, msg, 2021 info->snd_portid, info->snd_seq, 0, 2022 &state) < 0) { 2023 nlmsg_free(msg); 2024 return -ENOBUFS; 2025 } 2026 2027 return genlmsg_reply(msg, info); 2028 } 2029 2030 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = { 2031 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 }, 2032 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 }, 2033 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 }, 2034 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 }, 2035 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 }, 2036 }; 2037 2038 static int parse_txq_params(struct nlattr *tb[], 2039 struct ieee80211_txq_params *txq_params) 2040 { 2041 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] || 2042 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] || 2043 !tb[NL80211_TXQ_ATTR_AIFS]) 2044 return -EINVAL; 2045 2046 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]); 2047 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]); 2048 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]); 2049 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]); 2050 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]); 2051 2052 if (txq_params->ac >= NL80211_NUM_ACS) 2053 return -EINVAL; 2054 2055 return 0; 2056 } 2057 2058 static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev) 2059 { 2060 /* 2061 * You can only set the channel explicitly for WDS interfaces, 2062 * all others have their channel managed via their respective 2063 * "establish a connection" command (connect, join, ...) 2064 * 2065 * For AP/GO and mesh mode, the channel can be set with the 2066 * channel userspace API, but is only stored and passed to the 2067 * low-level driver when the AP starts or the mesh is joined. 2068 * This is for backward compatibility, userspace can also give 2069 * the channel in the start-ap or join-mesh commands instead. 2070 * 2071 * Monitors are special as they are normally slaved to 2072 * whatever else is going on, so they have their own special 2073 * operation to set the monitor channel if possible. 2074 */ 2075 return !wdev || 2076 wdev->iftype == NL80211_IFTYPE_AP || 2077 wdev->iftype == NL80211_IFTYPE_MESH_POINT || 2078 wdev->iftype == NL80211_IFTYPE_MONITOR || 2079 wdev->iftype == NL80211_IFTYPE_P2P_GO; 2080 } 2081 2082 static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev, 2083 struct genl_info *info, 2084 struct cfg80211_chan_def *chandef) 2085 { 2086 u32 control_freq; 2087 2088 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ]) 2089 return -EINVAL; 2090 2091 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]); 2092 2093 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq); 2094 chandef->width = NL80211_CHAN_WIDTH_20_NOHT; 2095 chandef->center_freq1 = control_freq; 2096 chandef->center_freq2 = 0; 2097 2098 /* Primary channel not allowed */ 2099 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED) 2100 return -EINVAL; 2101 2102 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) { 2103 enum nl80211_channel_type chantype; 2104 2105 chantype = nla_get_u32( 2106 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]); 2107 2108 switch (chantype) { 2109 case NL80211_CHAN_NO_HT: 2110 case NL80211_CHAN_HT20: 2111 case NL80211_CHAN_HT40PLUS: 2112 case NL80211_CHAN_HT40MINUS: 2113 cfg80211_chandef_create(chandef, chandef->chan, 2114 chantype); 2115 break; 2116 default: 2117 return -EINVAL; 2118 } 2119 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) { 2120 chandef->width = 2121 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]); 2122 if (info->attrs[NL80211_ATTR_CENTER_FREQ1]) 2123 chandef->center_freq1 = 2124 nla_get_u32( 2125 info->attrs[NL80211_ATTR_CENTER_FREQ1]); 2126 if (info->attrs[NL80211_ATTR_CENTER_FREQ2]) 2127 chandef->center_freq2 = 2128 nla_get_u32( 2129 info->attrs[NL80211_ATTR_CENTER_FREQ2]); 2130 } 2131 2132 if (!cfg80211_chandef_valid(chandef)) 2133 return -EINVAL; 2134 2135 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef, 2136 IEEE80211_CHAN_DISABLED)) 2137 return -EINVAL; 2138 2139 if ((chandef->width == NL80211_CHAN_WIDTH_5 || 2140 chandef->width == NL80211_CHAN_WIDTH_10) && 2141 !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ)) 2142 return -EINVAL; 2143 2144 return 0; 2145 } 2146 2147 static int __nl80211_set_channel(struct cfg80211_registered_device *rdev, 2148 struct net_device *dev, 2149 struct genl_info *info) 2150 { 2151 struct cfg80211_chan_def chandef; 2152 int result; 2153 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR; 2154 struct wireless_dev *wdev = NULL; 2155 2156 if (dev) 2157 wdev = dev->ieee80211_ptr; 2158 if (!nl80211_can_set_dev_channel(wdev)) 2159 return -EOPNOTSUPP; 2160 if (wdev) 2161 iftype = wdev->iftype; 2162 2163 result = nl80211_parse_chandef(rdev, info, &chandef); 2164 if (result) 2165 return result; 2166 2167 switch (iftype) { 2168 case NL80211_IFTYPE_AP: 2169 case NL80211_IFTYPE_P2P_GO: 2170 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef, 2171 iftype)) { 2172 result = -EINVAL; 2173 break; 2174 } 2175 if (wdev->beacon_interval) { 2176 if (!dev || !rdev->ops->set_ap_chanwidth || 2177 !(rdev->wiphy.features & 2178 NL80211_FEATURE_AP_MODE_CHAN_WIDTH_CHANGE)) { 2179 result = -EBUSY; 2180 break; 2181 } 2182 2183 /* Only allow dynamic channel width changes */ 2184 if (chandef.chan != wdev->preset_chandef.chan) { 2185 result = -EBUSY; 2186 break; 2187 } 2188 result = rdev_set_ap_chanwidth(rdev, dev, &chandef); 2189 if (result) 2190 break; 2191 } 2192 wdev->preset_chandef = chandef; 2193 result = 0; 2194 break; 2195 case NL80211_IFTYPE_MESH_POINT: 2196 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef); 2197 break; 2198 case NL80211_IFTYPE_MONITOR: 2199 result = cfg80211_set_monitor_channel(rdev, &chandef); 2200 break; 2201 default: 2202 result = -EINVAL; 2203 } 2204 2205 return result; 2206 } 2207 2208 static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info) 2209 { 2210 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2211 struct net_device *netdev = info->user_ptr[1]; 2212 2213 return __nl80211_set_channel(rdev, netdev, info); 2214 } 2215 2216 static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info) 2217 { 2218 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2219 struct net_device *dev = info->user_ptr[1]; 2220 struct wireless_dev *wdev = dev->ieee80211_ptr; 2221 const u8 *bssid; 2222 2223 if (!info->attrs[NL80211_ATTR_MAC]) 2224 return -EINVAL; 2225 2226 if (netif_running(dev)) 2227 return -EBUSY; 2228 2229 if (!rdev->ops->set_wds_peer) 2230 return -EOPNOTSUPP; 2231 2232 if (wdev->iftype != NL80211_IFTYPE_WDS) 2233 return -EOPNOTSUPP; 2234 2235 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 2236 return rdev_set_wds_peer(rdev, dev, bssid); 2237 } 2238 2239 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info) 2240 { 2241 struct cfg80211_registered_device *rdev; 2242 struct net_device *netdev = NULL; 2243 struct wireless_dev *wdev; 2244 int result = 0, rem_txq_params = 0; 2245 struct nlattr *nl_txq_params; 2246 u32 changed; 2247 u8 retry_short = 0, retry_long = 0; 2248 u32 frag_threshold = 0, rts_threshold = 0; 2249 u8 coverage_class = 0; 2250 2251 ASSERT_RTNL(); 2252 2253 /* 2254 * Try to find the wiphy and netdev. Normally this 2255 * function shouldn't need the netdev, but this is 2256 * done for backward compatibility -- previously 2257 * setting the channel was done per wiphy, but now 2258 * it is per netdev. Previous userland like hostapd 2259 * also passed a netdev to set_wiphy, so that it is 2260 * possible to let that go to the right netdev! 2261 */ 2262 2263 if (info->attrs[NL80211_ATTR_IFINDEX]) { 2264 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]); 2265 2266 netdev = __dev_get_by_index(genl_info_net(info), ifindex); 2267 if (netdev && netdev->ieee80211_ptr) 2268 rdev = wiphy_to_rdev(netdev->ieee80211_ptr->wiphy); 2269 else 2270 netdev = NULL; 2271 } 2272 2273 if (!netdev) { 2274 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info), 2275 info->attrs); 2276 if (IS_ERR(rdev)) 2277 return PTR_ERR(rdev); 2278 wdev = NULL; 2279 netdev = NULL; 2280 result = 0; 2281 } else 2282 wdev = netdev->ieee80211_ptr; 2283 2284 /* 2285 * end workaround code, by now the rdev is available 2286 * and locked, and wdev may or may not be NULL. 2287 */ 2288 2289 if (info->attrs[NL80211_ATTR_WIPHY_NAME]) 2290 result = cfg80211_dev_rename( 2291 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME])); 2292 2293 if (result) 2294 return result; 2295 2296 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) { 2297 struct ieee80211_txq_params txq_params; 2298 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1]; 2299 2300 if (!rdev->ops->set_txq_params) 2301 return -EOPNOTSUPP; 2302 2303 if (!netdev) 2304 return -EINVAL; 2305 2306 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 2307 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 2308 return -EINVAL; 2309 2310 if (!netif_running(netdev)) 2311 return -ENETDOWN; 2312 2313 nla_for_each_nested(nl_txq_params, 2314 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS], 2315 rem_txq_params) { 2316 result = nla_parse_nested(tb, NL80211_TXQ_ATTR_MAX, 2317 nl_txq_params, 2318 txq_params_policy); 2319 if (result) 2320 return result; 2321 result = parse_txq_params(tb, &txq_params); 2322 if (result) 2323 return result; 2324 2325 result = rdev_set_txq_params(rdev, netdev, 2326 &txq_params); 2327 if (result) 2328 return result; 2329 } 2330 } 2331 2332 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 2333 result = __nl80211_set_channel( 2334 rdev, 2335 nl80211_can_set_dev_channel(wdev) ? netdev : NULL, 2336 info); 2337 if (result) 2338 return result; 2339 } 2340 2341 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) { 2342 struct wireless_dev *txp_wdev = wdev; 2343 enum nl80211_tx_power_setting type; 2344 int idx, mbm = 0; 2345 2346 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER)) 2347 txp_wdev = NULL; 2348 2349 if (!rdev->ops->set_tx_power) 2350 return -EOPNOTSUPP; 2351 2352 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING; 2353 type = nla_get_u32(info->attrs[idx]); 2354 2355 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] && 2356 (type != NL80211_TX_POWER_AUTOMATIC)) 2357 return -EINVAL; 2358 2359 if (type != NL80211_TX_POWER_AUTOMATIC) { 2360 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL; 2361 mbm = nla_get_u32(info->attrs[idx]); 2362 } 2363 2364 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm); 2365 if (result) 2366 return result; 2367 } 2368 2369 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] && 2370 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) { 2371 u32 tx_ant, rx_ant; 2372 2373 if ((!rdev->wiphy.available_antennas_tx && 2374 !rdev->wiphy.available_antennas_rx) || 2375 !rdev->ops->set_antenna) 2376 return -EOPNOTSUPP; 2377 2378 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]); 2379 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]); 2380 2381 /* reject antenna configurations which don't match the 2382 * available antenna masks, except for the "all" mask */ 2383 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) || 2384 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) 2385 return -EINVAL; 2386 2387 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx; 2388 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx; 2389 2390 result = rdev_set_antenna(rdev, tx_ant, rx_ant); 2391 if (result) 2392 return result; 2393 } 2394 2395 changed = 0; 2396 2397 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) { 2398 retry_short = nla_get_u8( 2399 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]); 2400 if (retry_short == 0) 2401 return -EINVAL; 2402 2403 changed |= WIPHY_PARAM_RETRY_SHORT; 2404 } 2405 2406 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) { 2407 retry_long = nla_get_u8( 2408 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]); 2409 if (retry_long == 0) 2410 return -EINVAL; 2411 2412 changed |= WIPHY_PARAM_RETRY_LONG; 2413 } 2414 2415 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) { 2416 frag_threshold = nla_get_u32( 2417 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]); 2418 if (frag_threshold < 256) 2419 return -EINVAL; 2420 2421 if (frag_threshold != (u32) -1) { 2422 /* 2423 * Fragments (apart from the last one) are required to 2424 * have even length. Make the fragmentation code 2425 * simpler by stripping LSB should someone try to use 2426 * odd threshold value. 2427 */ 2428 frag_threshold &= ~0x1; 2429 } 2430 changed |= WIPHY_PARAM_FRAG_THRESHOLD; 2431 } 2432 2433 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) { 2434 rts_threshold = nla_get_u32( 2435 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]); 2436 changed |= WIPHY_PARAM_RTS_THRESHOLD; 2437 } 2438 2439 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) { 2440 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK]) 2441 return -EINVAL; 2442 2443 coverage_class = nla_get_u8( 2444 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]); 2445 changed |= WIPHY_PARAM_COVERAGE_CLASS; 2446 } 2447 2448 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK]) { 2449 if (!(rdev->wiphy.features & NL80211_FEATURE_ACKTO_ESTIMATION)) 2450 return -EOPNOTSUPP; 2451 2452 changed |= WIPHY_PARAM_DYN_ACK; 2453 } 2454 2455 if (changed) { 2456 u8 old_retry_short, old_retry_long; 2457 u32 old_frag_threshold, old_rts_threshold; 2458 u8 old_coverage_class; 2459 2460 if (!rdev->ops->set_wiphy_params) 2461 return -EOPNOTSUPP; 2462 2463 old_retry_short = rdev->wiphy.retry_short; 2464 old_retry_long = rdev->wiphy.retry_long; 2465 old_frag_threshold = rdev->wiphy.frag_threshold; 2466 old_rts_threshold = rdev->wiphy.rts_threshold; 2467 old_coverage_class = rdev->wiphy.coverage_class; 2468 2469 if (changed & WIPHY_PARAM_RETRY_SHORT) 2470 rdev->wiphy.retry_short = retry_short; 2471 if (changed & WIPHY_PARAM_RETRY_LONG) 2472 rdev->wiphy.retry_long = retry_long; 2473 if (changed & WIPHY_PARAM_FRAG_THRESHOLD) 2474 rdev->wiphy.frag_threshold = frag_threshold; 2475 if (changed & WIPHY_PARAM_RTS_THRESHOLD) 2476 rdev->wiphy.rts_threshold = rts_threshold; 2477 if (changed & WIPHY_PARAM_COVERAGE_CLASS) 2478 rdev->wiphy.coverage_class = coverage_class; 2479 2480 result = rdev_set_wiphy_params(rdev, changed); 2481 if (result) { 2482 rdev->wiphy.retry_short = old_retry_short; 2483 rdev->wiphy.retry_long = old_retry_long; 2484 rdev->wiphy.frag_threshold = old_frag_threshold; 2485 rdev->wiphy.rts_threshold = old_rts_threshold; 2486 rdev->wiphy.coverage_class = old_coverage_class; 2487 return result; 2488 } 2489 } 2490 return 0; 2491 } 2492 2493 static inline u64 wdev_id(struct wireless_dev *wdev) 2494 { 2495 return (u64)wdev->identifier | 2496 ((u64)wiphy_to_rdev(wdev->wiphy)->wiphy_idx << 32); 2497 } 2498 2499 static int nl80211_send_chandef(struct sk_buff *msg, 2500 const struct cfg80211_chan_def *chandef) 2501 { 2502 if (WARN_ON(!cfg80211_chandef_valid(chandef))) 2503 return -EINVAL; 2504 2505 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, 2506 chandef->chan->center_freq)) 2507 return -ENOBUFS; 2508 switch (chandef->width) { 2509 case NL80211_CHAN_WIDTH_20_NOHT: 2510 case NL80211_CHAN_WIDTH_20: 2511 case NL80211_CHAN_WIDTH_40: 2512 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, 2513 cfg80211_get_chandef_type(chandef))) 2514 return -ENOBUFS; 2515 break; 2516 default: 2517 break; 2518 } 2519 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width)) 2520 return -ENOBUFS; 2521 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1)) 2522 return -ENOBUFS; 2523 if (chandef->center_freq2 && 2524 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2)) 2525 return -ENOBUFS; 2526 return 0; 2527 } 2528 2529 static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags, 2530 struct cfg80211_registered_device *rdev, 2531 struct wireless_dev *wdev, bool removal) 2532 { 2533 struct net_device *dev = wdev->netdev; 2534 u8 cmd = NL80211_CMD_NEW_INTERFACE; 2535 void *hdr; 2536 2537 if (removal) 2538 cmd = NL80211_CMD_DEL_INTERFACE; 2539 2540 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 2541 if (!hdr) 2542 return -1; 2543 2544 if (dev && 2545 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 2546 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name))) 2547 goto nla_put_failure; 2548 2549 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 2550 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) || 2551 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 2552 NL80211_ATTR_PAD) || 2553 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) || 2554 nla_put_u32(msg, NL80211_ATTR_GENERATION, 2555 rdev->devlist_generation ^ 2556 (cfg80211_rdev_list_generation << 2))) 2557 goto nla_put_failure; 2558 2559 if (rdev->ops->get_channel) { 2560 int ret; 2561 struct cfg80211_chan_def chandef; 2562 2563 ret = rdev_get_channel(rdev, wdev, &chandef); 2564 if (ret == 0) { 2565 if (nl80211_send_chandef(msg, &chandef)) 2566 goto nla_put_failure; 2567 } 2568 } 2569 2570 if (rdev->ops->get_tx_power) { 2571 int dbm, ret; 2572 2573 ret = rdev_get_tx_power(rdev, wdev, &dbm); 2574 if (ret == 0 && 2575 nla_put_u32(msg, NL80211_ATTR_WIPHY_TX_POWER_LEVEL, 2576 DBM_TO_MBM(dbm))) 2577 goto nla_put_failure; 2578 } 2579 2580 if (wdev->ssid_len) { 2581 if (nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid)) 2582 goto nla_put_failure; 2583 } 2584 2585 genlmsg_end(msg, hdr); 2586 return 0; 2587 2588 nla_put_failure: 2589 genlmsg_cancel(msg, hdr); 2590 return -EMSGSIZE; 2591 } 2592 2593 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb) 2594 { 2595 int wp_idx = 0; 2596 int if_idx = 0; 2597 int wp_start = cb->args[0]; 2598 int if_start = cb->args[1]; 2599 int filter_wiphy = -1; 2600 struct cfg80211_registered_device *rdev; 2601 struct wireless_dev *wdev; 2602 2603 rtnl_lock(); 2604 if (!cb->args[2]) { 2605 struct nl80211_dump_wiphy_state state = { 2606 .filter_wiphy = -1, 2607 }; 2608 int ret; 2609 2610 ret = nl80211_dump_wiphy_parse(skb, cb, &state); 2611 if (ret) 2612 return ret; 2613 2614 filter_wiphy = state.filter_wiphy; 2615 2616 /* 2617 * if filtering, set cb->args[2] to +1 since 0 is the default 2618 * value needed to determine that parsing is necessary. 2619 */ 2620 if (filter_wiphy >= 0) 2621 cb->args[2] = filter_wiphy + 1; 2622 else 2623 cb->args[2] = -1; 2624 } else if (cb->args[2] > 0) { 2625 filter_wiphy = cb->args[2] - 1; 2626 } 2627 2628 list_for_each_entry(rdev, &cfg80211_rdev_list, list) { 2629 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk))) 2630 continue; 2631 if (wp_idx < wp_start) { 2632 wp_idx++; 2633 continue; 2634 } 2635 2636 if (filter_wiphy >= 0 && filter_wiphy != rdev->wiphy_idx) 2637 continue; 2638 2639 if_idx = 0; 2640 2641 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) { 2642 if (if_idx < if_start) { 2643 if_idx++; 2644 continue; 2645 } 2646 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid, 2647 cb->nlh->nlmsg_seq, NLM_F_MULTI, 2648 rdev, wdev, false) < 0) { 2649 goto out; 2650 } 2651 if_idx++; 2652 } 2653 2654 wp_idx++; 2655 } 2656 out: 2657 rtnl_unlock(); 2658 2659 cb->args[0] = wp_idx; 2660 cb->args[1] = if_idx; 2661 2662 return skb->len; 2663 } 2664 2665 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info) 2666 { 2667 struct sk_buff *msg; 2668 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2669 struct wireless_dev *wdev = info->user_ptr[1]; 2670 2671 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 2672 if (!msg) 2673 return -ENOMEM; 2674 2675 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0, 2676 rdev, wdev, false) < 0) { 2677 nlmsg_free(msg); 2678 return -ENOBUFS; 2679 } 2680 2681 return genlmsg_reply(msg, info); 2682 } 2683 2684 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = { 2685 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG }, 2686 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG }, 2687 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG }, 2688 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG }, 2689 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG }, 2690 [NL80211_MNTR_FLAG_ACTIVE] = { .type = NLA_FLAG }, 2691 }; 2692 2693 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags) 2694 { 2695 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1]; 2696 int flag; 2697 2698 *mntrflags = 0; 2699 2700 if (!nla) 2701 return -EINVAL; 2702 2703 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX, 2704 nla, mntr_flags_policy)) 2705 return -EINVAL; 2706 2707 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++) 2708 if (flags[flag]) 2709 *mntrflags |= (1<<flag); 2710 2711 return 0; 2712 } 2713 2714 static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev, 2715 struct net_device *netdev, u8 use_4addr, 2716 enum nl80211_iftype iftype) 2717 { 2718 if (!use_4addr) { 2719 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT)) 2720 return -EBUSY; 2721 return 0; 2722 } 2723 2724 switch (iftype) { 2725 case NL80211_IFTYPE_AP_VLAN: 2726 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP) 2727 return 0; 2728 break; 2729 case NL80211_IFTYPE_STATION: 2730 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION) 2731 return 0; 2732 break; 2733 default: 2734 break; 2735 } 2736 2737 return -EOPNOTSUPP; 2738 } 2739 2740 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info) 2741 { 2742 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2743 struct vif_params params; 2744 int err; 2745 enum nl80211_iftype otype, ntype; 2746 struct net_device *dev = info->user_ptr[1]; 2747 u32 _flags, *flags = NULL; 2748 bool change = false; 2749 2750 memset(¶ms, 0, sizeof(params)); 2751 2752 otype = ntype = dev->ieee80211_ptr->iftype; 2753 2754 if (info->attrs[NL80211_ATTR_IFTYPE]) { 2755 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]); 2756 if (otype != ntype) 2757 change = true; 2758 if (ntype > NL80211_IFTYPE_MAX) 2759 return -EINVAL; 2760 } 2761 2762 if (info->attrs[NL80211_ATTR_MESH_ID]) { 2763 struct wireless_dev *wdev = dev->ieee80211_ptr; 2764 2765 if (ntype != NL80211_IFTYPE_MESH_POINT) 2766 return -EINVAL; 2767 if (netif_running(dev)) 2768 return -EBUSY; 2769 2770 wdev_lock(wdev); 2771 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN != 2772 IEEE80211_MAX_MESH_ID_LEN); 2773 wdev->mesh_id_up_len = 2774 nla_len(info->attrs[NL80211_ATTR_MESH_ID]); 2775 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]), 2776 wdev->mesh_id_up_len); 2777 wdev_unlock(wdev); 2778 } 2779 2780 if (info->attrs[NL80211_ATTR_4ADDR]) { 2781 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]); 2782 change = true; 2783 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype); 2784 if (err) 2785 return err; 2786 } else { 2787 params.use_4addr = -1; 2788 } 2789 2790 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) { 2791 if (ntype != NL80211_IFTYPE_MONITOR) 2792 return -EINVAL; 2793 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS], 2794 &_flags); 2795 if (err) 2796 return err; 2797 2798 flags = &_flags; 2799 change = true; 2800 } 2801 2802 if (info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]) { 2803 const u8 *mumimo_groups; 2804 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER; 2805 2806 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag)) 2807 return -EOPNOTSUPP; 2808 2809 mumimo_groups = 2810 nla_data(info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]); 2811 2812 /* bits 0 and 63 are reserved and must be zero */ 2813 if ((mumimo_groups[0] & BIT(7)) || 2814 (mumimo_groups[VHT_MUMIMO_GROUPS_DATA_LEN - 1] & BIT(0))) 2815 return -EINVAL; 2816 2817 memcpy(params.vht_mumimo_groups, mumimo_groups, 2818 VHT_MUMIMO_GROUPS_DATA_LEN); 2819 change = true; 2820 } 2821 2822 if (info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR]) { 2823 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER; 2824 2825 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag)) 2826 return -EOPNOTSUPP; 2827 2828 nla_memcpy(params.macaddr, 2829 info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR], 2830 ETH_ALEN); 2831 change = true; 2832 } 2833 2834 if (flags && (*flags & MONITOR_FLAG_ACTIVE) && 2835 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR)) 2836 return -EOPNOTSUPP; 2837 2838 if (change) 2839 err = cfg80211_change_iface(rdev, dev, ntype, flags, ¶ms); 2840 else 2841 err = 0; 2842 2843 if (!err && params.use_4addr != -1) 2844 dev->ieee80211_ptr->use_4addr = params.use_4addr; 2845 2846 return err; 2847 } 2848 2849 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info) 2850 { 2851 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2852 struct vif_params params; 2853 struct wireless_dev *wdev; 2854 struct sk_buff *msg; 2855 int err; 2856 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED; 2857 u32 flags; 2858 2859 /* to avoid failing a new interface creation due to pending removal */ 2860 cfg80211_destroy_ifaces(rdev); 2861 2862 memset(¶ms, 0, sizeof(params)); 2863 2864 if (!info->attrs[NL80211_ATTR_IFNAME]) 2865 return -EINVAL; 2866 2867 if (info->attrs[NL80211_ATTR_IFTYPE]) { 2868 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]); 2869 if (type > NL80211_IFTYPE_MAX) 2870 return -EINVAL; 2871 } 2872 2873 if (!rdev->ops->add_virtual_intf || 2874 !(rdev->wiphy.interface_modes & (1 << type))) 2875 return -EOPNOTSUPP; 2876 2877 if ((type == NL80211_IFTYPE_P2P_DEVICE || type == NL80211_IFTYPE_NAN || 2878 rdev->wiphy.features & NL80211_FEATURE_MAC_ON_CREATE) && 2879 info->attrs[NL80211_ATTR_MAC]) { 2880 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC], 2881 ETH_ALEN); 2882 if (!is_valid_ether_addr(params.macaddr)) 2883 return -EADDRNOTAVAIL; 2884 } 2885 2886 if (info->attrs[NL80211_ATTR_4ADDR]) { 2887 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]); 2888 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type); 2889 if (err) 2890 return err; 2891 } 2892 2893 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ? 2894 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL, 2895 &flags); 2896 2897 if (!err && (flags & MONITOR_FLAG_ACTIVE) && 2898 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR)) 2899 return -EOPNOTSUPP; 2900 2901 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 2902 if (!msg) 2903 return -ENOMEM; 2904 2905 wdev = rdev_add_virtual_intf(rdev, 2906 nla_data(info->attrs[NL80211_ATTR_IFNAME]), 2907 NET_NAME_USER, type, err ? NULL : &flags, 2908 ¶ms); 2909 if (WARN_ON(!wdev)) { 2910 nlmsg_free(msg); 2911 return -EPROTO; 2912 } else if (IS_ERR(wdev)) { 2913 nlmsg_free(msg); 2914 return PTR_ERR(wdev); 2915 } 2916 2917 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) 2918 wdev->owner_nlportid = info->snd_portid; 2919 2920 switch (type) { 2921 case NL80211_IFTYPE_MESH_POINT: 2922 if (!info->attrs[NL80211_ATTR_MESH_ID]) 2923 break; 2924 wdev_lock(wdev); 2925 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN != 2926 IEEE80211_MAX_MESH_ID_LEN); 2927 wdev->mesh_id_up_len = 2928 nla_len(info->attrs[NL80211_ATTR_MESH_ID]); 2929 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]), 2930 wdev->mesh_id_up_len); 2931 wdev_unlock(wdev); 2932 break; 2933 case NL80211_IFTYPE_NAN: 2934 case NL80211_IFTYPE_P2P_DEVICE: 2935 /* 2936 * P2P Device and NAN do not have a netdev, so don't go 2937 * through the netdev notifier and must be added here 2938 */ 2939 mutex_init(&wdev->mtx); 2940 INIT_LIST_HEAD(&wdev->event_list); 2941 spin_lock_init(&wdev->event_lock); 2942 INIT_LIST_HEAD(&wdev->mgmt_registrations); 2943 spin_lock_init(&wdev->mgmt_registrations_lock); 2944 2945 wdev->identifier = ++rdev->wdev_id; 2946 list_add_rcu(&wdev->list, &rdev->wiphy.wdev_list); 2947 rdev->devlist_generation++; 2948 break; 2949 default: 2950 break; 2951 } 2952 2953 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0, 2954 rdev, wdev, false) < 0) { 2955 nlmsg_free(msg); 2956 return -ENOBUFS; 2957 } 2958 2959 /* 2960 * For wdevs which have no associated netdev object (e.g. of type 2961 * NL80211_IFTYPE_P2P_DEVICE), emit the NEW_INTERFACE event here. 2962 * For all other types, the event will be generated from the 2963 * netdev notifier 2964 */ 2965 if (!wdev->netdev) 2966 nl80211_notify_iface(rdev, wdev, NL80211_CMD_NEW_INTERFACE); 2967 2968 return genlmsg_reply(msg, info); 2969 } 2970 2971 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info) 2972 { 2973 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2974 struct wireless_dev *wdev = info->user_ptr[1]; 2975 2976 if (!rdev->ops->del_virtual_intf) 2977 return -EOPNOTSUPP; 2978 2979 /* 2980 * If we remove a wireless device without a netdev then clear 2981 * user_ptr[1] so that nl80211_post_doit won't dereference it 2982 * to check if it needs to do dev_put(). Otherwise it crashes 2983 * since the wdev has been freed, unlike with a netdev where 2984 * we need the dev_put() for the netdev to really be freed. 2985 */ 2986 if (!wdev->netdev) 2987 info->user_ptr[1] = NULL; 2988 2989 return rdev_del_virtual_intf(rdev, wdev); 2990 } 2991 2992 static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info) 2993 { 2994 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2995 struct net_device *dev = info->user_ptr[1]; 2996 u16 noack_map; 2997 2998 if (!info->attrs[NL80211_ATTR_NOACK_MAP]) 2999 return -EINVAL; 3000 3001 if (!rdev->ops->set_noack_map) 3002 return -EOPNOTSUPP; 3003 3004 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]); 3005 3006 return rdev_set_noack_map(rdev, dev, noack_map); 3007 } 3008 3009 struct get_key_cookie { 3010 struct sk_buff *msg; 3011 int error; 3012 int idx; 3013 }; 3014 3015 static void get_key_callback(void *c, struct key_params *params) 3016 { 3017 struct nlattr *key; 3018 struct get_key_cookie *cookie = c; 3019 3020 if ((params->key && 3021 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA, 3022 params->key_len, params->key)) || 3023 (params->seq && 3024 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ, 3025 params->seq_len, params->seq)) || 3026 (params->cipher && 3027 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER, 3028 params->cipher))) 3029 goto nla_put_failure; 3030 3031 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY); 3032 if (!key) 3033 goto nla_put_failure; 3034 3035 if ((params->key && 3036 nla_put(cookie->msg, NL80211_KEY_DATA, 3037 params->key_len, params->key)) || 3038 (params->seq && 3039 nla_put(cookie->msg, NL80211_KEY_SEQ, 3040 params->seq_len, params->seq)) || 3041 (params->cipher && 3042 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER, 3043 params->cipher))) 3044 goto nla_put_failure; 3045 3046 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx)) 3047 goto nla_put_failure; 3048 3049 nla_nest_end(cookie->msg, key); 3050 3051 return; 3052 nla_put_failure: 3053 cookie->error = 1; 3054 } 3055 3056 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info) 3057 { 3058 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3059 int err; 3060 struct net_device *dev = info->user_ptr[1]; 3061 u8 key_idx = 0; 3062 const u8 *mac_addr = NULL; 3063 bool pairwise; 3064 struct get_key_cookie cookie = { 3065 .error = 0, 3066 }; 3067 void *hdr; 3068 struct sk_buff *msg; 3069 3070 if (info->attrs[NL80211_ATTR_KEY_IDX]) 3071 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]); 3072 3073 if (key_idx > 5) 3074 return -EINVAL; 3075 3076 if (info->attrs[NL80211_ATTR_MAC]) 3077 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 3078 3079 pairwise = !!mac_addr; 3080 if (info->attrs[NL80211_ATTR_KEY_TYPE]) { 3081 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]); 3082 3083 if (kt >= NUM_NL80211_KEYTYPES) 3084 return -EINVAL; 3085 if (kt != NL80211_KEYTYPE_GROUP && 3086 kt != NL80211_KEYTYPE_PAIRWISE) 3087 return -EINVAL; 3088 pairwise = kt == NL80211_KEYTYPE_PAIRWISE; 3089 } 3090 3091 if (!rdev->ops->get_key) 3092 return -EOPNOTSUPP; 3093 3094 if (!pairwise && mac_addr && !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)) 3095 return -ENOENT; 3096 3097 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 3098 if (!msg) 3099 return -ENOMEM; 3100 3101 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 3102 NL80211_CMD_NEW_KEY); 3103 if (!hdr) 3104 goto nla_put_failure; 3105 3106 cookie.msg = msg; 3107 cookie.idx = key_idx; 3108 3109 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 3110 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx)) 3111 goto nla_put_failure; 3112 if (mac_addr && 3113 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr)) 3114 goto nla_put_failure; 3115 3116 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie, 3117 get_key_callback); 3118 3119 if (err) 3120 goto free_msg; 3121 3122 if (cookie.error) 3123 goto nla_put_failure; 3124 3125 genlmsg_end(msg, hdr); 3126 return genlmsg_reply(msg, info); 3127 3128 nla_put_failure: 3129 err = -ENOBUFS; 3130 free_msg: 3131 nlmsg_free(msg); 3132 return err; 3133 } 3134 3135 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info) 3136 { 3137 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3138 struct key_parse key; 3139 int err; 3140 struct net_device *dev = info->user_ptr[1]; 3141 3142 err = nl80211_parse_key(info, &key); 3143 if (err) 3144 return err; 3145 3146 if (key.idx < 0) 3147 return -EINVAL; 3148 3149 /* only support setting default key */ 3150 if (!key.def && !key.defmgmt) 3151 return -EINVAL; 3152 3153 wdev_lock(dev->ieee80211_ptr); 3154 3155 if (key.def) { 3156 if (!rdev->ops->set_default_key) { 3157 err = -EOPNOTSUPP; 3158 goto out; 3159 } 3160 3161 err = nl80211_key_allowed(dev->ieee80211_ptr); 3162 if (err) 3163 goto out; 3164 3165 err = rdev_set_default_key(rdev, dev, key.idx, 3166 key.def_uni, key.def_multi); 3167 3168 if (err) 3169 goto out; 3170 3171 #ifdef CONFIG_CFG80211_WEXT 3172 dev->ieee80211_ptr->wext.default_key = key.idx; 3173 #endif 3174 } else { 3175 if (key.def_uni || !key.def_multi) { 3176 err = -EINVAL; 3177 goto out; 3178 } 3179 3180 if (!rdev->ops->set_default_mgmt_key) { 3181 err = -EOPNOTSUPP; 3182 goto out; 3183 } 3184 3185 err = nl80211_key_allowed(dev->ieee80211_ptr); 3186 if (err) 3187 goto out; 3188 3189 err = rdev_set_default_mgmt_key(rdev, dev, key.idx); 3190 if (err) 3191 goto out; 3192 3193 #ifdef CONFIG_CFG80211_WEXT 3194 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx; 3195 #endif 3196 } 3197 3198 out: 3199 wdev_unlock(dev->ieee80211_ptr); 3200 3201 return err; 3202 } 3203 3204 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info) 3205 { 3206 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3207 int err; 3208 struct net_device *dev = info->user_ptr[1]; 3209 struct key_parse key; 3210 const u8 *mac_addr = NULL; 3211 3212 err = nl80211_parse_key(info, &key); 3213 if (err) 3214 return err; 3215 3216 if (!key.p.key) 3217 return -EINVAL; 3218 3219 if (info->attrs[NL80211_ATTR_MAC]) 3220 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 3221 3222 if (key.type == -1) { 3223 if (mac_addr) 3224 key.type = NL80211_KEYTYPE_PAIRWISE; 3225 else 3226 key.type = NL80211_KEYTYPE_GROUP; 3227 } 3228 3229 /* for now */ 3230 if (key.type != NL80211_KEYTYPE_PAIRWISE && 3231 key.type != NL80211_KEYTYPE_GROUP) 3232 return -EINVAL; 3233 3234 if (!rdev->ops->add_key) 3235 return -EOPNOTSUPP; 3236 3237 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, 3238 key.type == NL80211_KEYTYPE_PAIRWISE, 3239 mac_addr)) 3240 return -EINVAL; 3241 3242 wdev_lock(dev->ieee80211_ptr); 3243 err = nl80211_key_allowed(dev->ieee80211_ptr); 3244 if (!err) 3245 err = rdev_add_key(rdev, dev, key.idx, 3246 key.type == NL80211_KEYTYPE_PAIRWISE, 3247 mac_addr, &key.p); 3248 wdev_unlock(dev->ieee80211_ptr); 3249 3250 return err; 3251 } 3252 3253 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info) 3254 { 3255 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3256 int err; 3257 struct net_device *dev = info->user_ptr[1]; 3258 u8 *mac_addr = NULL; 3259 struct key_parse key; 3260 3261 err = nl80211_parse_key(info, &key); 3262 if (err) 3263 return err; 3264 3265 if (info->attrs[NL80211_ATTR_MAC]) 3266 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 3267 3268 if (key.type == -1) { 3269 if (mac_addr) 3270 key.type = NL80211_KEYTYPE_PAIRWISE; 3271 else 3272 key.type = NL80211_KEYTYPE_GROUP; 3273 } 3274 3275 /* for now */ 3276 if (key.type != NL80211_KEYTYPE_PAIRWISE && 3277 key.type != NL80211_KEYTYPE_GROUP) 3278 return -EINVAL; 3279 3280 if (!rdev->ops->del_key) 3281 return -EOPNOTSUPP; 3282 3283 wdev_lock(dev->ieee80211_ptr); 3284 err = nl80211_key_allowed(dev->ieee80211_ptr); 3285 3286 if (key.type == NL80211_KEYTYPE_GROUP && mac_addr && 3287 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)) 3288 err = -ENOENT; 3289 3290 if (!err) 3291 err = rdev_del_key(rdev, dev, key.idx, 3292 key.type == NL80211_KEYTYPE_PAIRWISE, 3293 mac_addr); 3294 3295 #ifdef CONFIG_CFG80211_WEXT 3296 if (!err) { 3297 if (key.idx == dev->ieee80211_ptr->wext.default_key) 3298 dev->ieee80211_ptr->wext.default_key = -1; 3299 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key) 3300 dev->ieee80211_ptr->wext.default_mgmt_key = -1; 3301 } 3302 #endif 3303 wdev_unlock(dev->ieee80211_ptr); 3304 3305 return err; 3306 } 3307 3308 /* This function returns an error or the number of nested attributes */ 3309 static int validate_acl_mac_addrs(struct nlattr *nl_attr) 3310 { 3311 struct nlattr *attr; 3312 int n_entries = 0, tmp; 3313 3314 nla_for_each_nested(attr, nl_attr, tmp) { 3315 if (nla_len(attr) != ETH_ALEN) 3316 return -EINVAL; 3317 3318 n_entries++; 3319 } 3320 3321 return n_entries; 3322 } 3323 3324 /* 3325 * This function parses ACL information and allocates memory for ACL data. 3326 * On successful return, the calling function is responsible to free the 3327 * ACL buffer returned by this function. 3328 */ 3329 static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy, 3330 struct genl_info *info) 3331 { 3332 enum nl80211_acl_policy acl_policy; 3333 struct nlattr *attr; 3334 struct cfg80211_acl_data *acl; 3335 int i = 0, n_entries, tmp; 3336 3337 if (!wiphy->max_acl_mac_addrs) 3338 return ERR_PTR(-EOPNOTSUPP); 3339 3340 if (!info->attrs[NL80211_ATTR_ACL_POLICY]) 3341 return ERR_PTR(-EINVAL); 3342 3343 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]); 3344 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED && 3345 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED) 3346 return ERR_PTR(-EINVAL); 3347 3348 if (!info->attrs[NL80211_ATTR_MAC_ADDRS]) 3349 return ERR_PTR(-EINVAL); 3350 3351 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]); 3352 if (n_entries < 0) 3353 return ERR_PTR(n_entries); 3354 3355 if (n_entries > wiphy->max_acl_mac_addrs) 3356 return ERR_PTR(-ENOTSUPP); 3357 3358 acl = kzalloc(sizeof(*acl) + (sizeof(struct mac_address) * n_entries), 3359 GFP_KERNEL); 3360 if (!acl) 3361 return ERR_PTR(-ENOMEM); 3362 3363 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) { 3364 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN); 3365 i++; 3366 } 3367 3368 acl->n_acl_entries = n_entries; 3369 acl->acl_policy = acl_policy; 3370 3371 return acl; 3372 } 3373 3374 static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info) 3375 { 3376 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3377 struct net_device *dev = info->user_ptr[1]; 3378 struct cfg80211_acl_data *acl; 3379 int err; 3380 3381 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 3382 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3383 return -EOPNOTSUPP; 3384 3385 if (!dev->ieee80211_ptr->beacon_interval) 3386 return -EINVAL; 3387 3388 acl = parse_acl_data(&rdev->wiphy, info); 3389 if (IS_ERR(acl)) 3390 return PTR_ERR(acl); 3391 3392 err = rdev_set_mac_acl(rdev, dev, acl); 3393 3394 kfree(acl); 3395 3396 return err; 3397 } 3398 3399 static u32 rateset_to_mask(struct ieee80211_supported_band *sband, 3400 u8 *rates, u8 rates_len) 3401 { 3402 u8 i; 3403 u32 mask = 0; 3404 3405 for (i = 0; i < rates_len; i++) { 3406 int rate = (rates[i] & 0x7f) * 5; 3407 int ridx; 3408 3409 for (ridx = 0; ridx < sband->n_bitrates; ridx++) { 3410 struct ieee80211_rate *srate = 3411 &sband->bitrates[ridx]; 3412 if (rate == srate->bitrate) { 3413 mask |= 1 << ridx; 3414 break; 3415 } 3416 } 3417 if (ridx == sband->n_bitrates) 3418 return 0; /* rate not found */ 3419 } 3420 3421 return mask; 3422 } 3423 3424 static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband, 3425 u8 *rates, u8 rates_len, 3426 u8 mcs[IEEE80211_HT_MCS_MASK_LEN]) 3427 { 3428 u8 i; 3429 3430 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN); 3431 3432 for (i = 0; i < rates_len; i++) { 3433 int ridx, rbit; 3434 3435 ridx = rates[i] / 8; 3436 rbit = BIT(rates[i] % 8); 3437 3438 /* check validity */ 3439 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN)) 3440 return false; 3441 3442 /* check availability */ 3443 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit) 3444 mcs[ridx] |= rbit; 3445 else 3446 return false; 3447 } 3448 3449 return true; 3450 } 3451 3452 static u16 vht_mcs_map_to_mcs_mask(u8 vht_mcs_map) 3453 { 3454 u16 mcs_mask = 0; 3455 3456 switch (vht_mcs_map) { 3457 case IEEE80211_VHT_MCS_NOT_SUPPORTED: 3458 break; 3459 case IEEE80211_VHT_MCS_SUPPORT_0_7: 3460 mcs_mask = 0x00FF; 3461 break; 3462 case IEEE80211_VHT_MCS_SUPPORT_0_8: 3463 mcs_mask = 0x01FF; 3464 break; 3465 case IEEE80211_VHT_MCS_SUPPORT_0_9: 3466 mcs_mask = 0x03FF; 3467 break; 3468 default: 3469 break; 3470 } 3471 3472 return mcs_mask; 3473 } 3474 3475 static void vht_build_mcs_mask(u16 vht_mcs_map, 3476 u16 vht_mcs_mask[NL80211_VHT_NSS_MAX]) 3477 { 3478 u8 nss; 3479 3480 for (nss = 0; nss < NL80211_VHT_NSS_MAX; nss++) { 3481 vht_mcs_mask[nss] = vht_mcs_map_to_mcs_mask(vht_mcs_map & 0x03); 3482 vht_mcs_map >>= 2; 3483 } 3484 } 3485 3486 static bool vht_set_mcs_mask(struct ieee80211_supported_band *sband, 3487 struct nl80211_txrate_vht *txrate, 3488 u16 mcs[NL80211_VHT_NSS_MAX]) 3489 { 3490 u16 tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map); 3491 u16 tx_mcs_mask[NL80211_VHT_NSS_MAX] = {}; 3492 u8 i; 3493 3494 if (!sband->vht_cap.vht_supported) 3495 return false; 3496 3497 memset(mcs, 0, sizeof(u16) * NL80211_VHT_NSS_MAX); 3498 3499 /* Build vht_mcs_mask from VHT capabilities */ 3500 vht_build_mcs_mask(tx_mcs_map, tx_mcs_mask); 3501 3502 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) { 3503 if ((tx_mcs_mask[i] & txrate->mcs[i]) == txrate->mcs[i]) 3504 mcs[i] = txrate->mcs[i]; 3505 else 3506 return false; 3507 } 3508 3509 return true; 3510 } 3511 3512 static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = { 3513 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY, 3514 .len = NL80211_MAX_SUPP_RATES }, 3515 [NL80211_TXRATE_HT] = { .type = NLA_BINARY, 3516 .len = NL80211_MAX_SUPP_HT_RATES }, 3517 [NL80211_TXRATE_VHT] = { .len = sizeof(struct nl80211_txrate_vht)}, 3518 [NL80211_TXRATE_GI] = { .type = NLA_U8 }, 3519 }; 3520 3521 static int nl80211_parse_tx_bitrate_mask(struct genl_info *info, 3522 struct cfg80211_bitrate_mask *mask) 3523 { 3524 struct nlattr *tb[NL80211_TXRATE_MAX + 1]; 3525 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3526 int rem, i; 3527 struct nlattr *tx_rates; 3528 struct ieee80211_supported_band *sband; 3529 u16 vht_tx_mcs_map; 3530 3531 memset(mask, 0, sizeof(*mask)); 3532 /* Default to all rates enabled */ 3533 for (i = 0; i < NUM_NL80211_BANDS; i++) { 3534 sband = rdev->wiphy.bands[i]; 3535 3536 if (!sband) 3537 continue; 3538 3539 mask->control[i].legacy = (1 << sband->n_bitrates) - 1; 3540 memcpy(mask->control[i].ht_mcs, 3541 sband->ht_cap.mcs.rx_mask, 3542 sizeof(mask->control[i].ht_mcs)); 3543 3544 if (!sband->vht_cap.vht_supported) 3545 continue; 3546 3547 vht_tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map); 3548 vht_build_mcs_mask(vht_tx_mcs_map, mask->control[i].vht_mcs); 3549 } 3550 3551 /* if no rates are given set it back to the defaults */ 3552 if (!info->attrs[NL80211_ATTR_TX_RATES]) 3553 goto out; 3554 3555 /* The nested attribute uses enum nl80211_band as the index. This maps 3556 * directly to the enum nl80211_band values used in cfg80211. 3557 */ 3558 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8); 3559 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem) { 3560 enum nl80211_band band = nla_type(tx_rates); 3561 int err; 3562 3563 if (band < 0 || band >= NUM_NL80211_BANDS) 3564 return -EINVAL; 3565 sband = rdev->wiphy.bands[band]; 3566 if (sband == NULL) 3567 return -EINVAL; 3568 err = nla_parse_nested(tb, NL80211_TXRATE_MAX, tx_rates, 3569 nl80211_txattr_policy); 3570 if (err) 3571 return err; 3572 if (tb[NL80211_TXRATE_LEGACY]) { 3573 mask->control[band].legacy = rateset_to_mask( 3574 sband, 3575 nla_data(tb[NL80211_TXRATE_LEGACY]), 3576 nla_len(tb[NL80211_TXRATE_LEGACY])); 3577 if ((mask->control[band].legacy == 0) && 3578 nla_len(tb[NL80211_TXRATE_LEGACY])) 3579 return -EINVAL; 3580 } 3581 if (tb[NL80211_TXRATE_HT]) { 3582 if (!ht_rateset_to_mask( 3583 sband, 3584 nla_data(tb[NL80211_TXRATE_HT]), 3585 nla_len(tb[NL80211_TXRATE_HT]), 3586 mask->control[band].ht_mcs)) 3587 return -EINVAL; 3588 } 3589 if (tb[NL80211_TXRATE_VHT]) { 3590 if (!vht_set_mcs_mask( 3591 sband, 3592 nla_data(tb[NL80211_TXRATE_VHT]), 3593 mask->control[band].vht_mcs)) 3594 return -EINVAL; 3595 } 3596 if (tb[NL80211_TXRATE_GI]) { 3597 mask->control[band].gi = 3598 nla_get_u8(tb[NL80211_TXRATE_GI]); 3599 if (mask->control[band].gi > NL80211_TXRATE_FORCE_LGI) 3600 return -EINVAL; 3601 } 3602 3603 if (mask->control[band].legacy == 0) { 3604 /* don't allow empty legacy rates if HT or VHT 3605 * are not even supported. 3606 */ 3607 if (!(rdev->wiphy.bands[band]->ht_cap.ht_supported || 3608 rdev->wiphy.bands[band]->vht_cap.vht_supported)) 3609 return -EINVAL; 3610 3611 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++) 3612 if (mask->control[band].ht_mcs[i]) 3613 goto out; 3614 3615 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) 3616 if (mask->control[band].vht_mcs[i]) 3617 goto out; 3618 3619 /* legacy and mcs rates may not be both empty */ 3620 return -EINVAL; 3621 } 3622 } 3623 3624 out: 3625 return 0; 3626 } 3627 3628 static int validate_beacon_tx_rate(struct cfg80211_registered_device *rdev, 3629 enum nl80211_band band, 3630 struct cfg80211_bitrate_mask *beacon_rate) 3631 { 3632 u32 count_ht, count_vht, i; 3633 u32 rate = beacon_rate->control[band].legacy; 3634 3635 /* Allow only one rate */ 3636 if (hweight32(rate) > 1) 3637 return -EINVAL; 3638 3639 count_ht = 0; 3640 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++) { 3641 if (hweight8(beacon_rate->control[band].ht_mcs[i]) > 1) { 3642 return -EINVAL; 3643 } else if (beacon_rate->control[band].ht_mcs[i]) { 3644 count_ht++; 3645 if (count_ht > 1) 3646 return -EINVAL; 3647 } 3648 if (count_ht && rate) 3649 return -EINVAL; 3650 } 3651 3652 count_vht = 0; 3653 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) { 3654 if (hweight16(beacon_rate->control[band].vht_mcs[i]) > 1) { 3655 return -EINVAL; 3656 } else if (beacon_rate->control[band].vht_mcs[i]) { 3657 count_vht++; 3658 if (count_vht > 1) 3659 return -EINVAL; 3660 } 3661 if (count_vht && rate) 3662 return -EINVAL; 3663 } 3664 3665 if ((count_ht && count_vht) || (!rate && !count_ht && !count_vht)) 3666 return -EINVAL; 3667 3668 if (rate && 3669 !wiphy_ext_feature_isset(&rdev->wiphy, 3670 NL80211_EXT_FEATURE_BEACON_RATE_LEGACY)) 3671 return -EINVAL; 3672 if (count_ht && 3673 !wiphy_ext_feature_isset(&rdev->wiphy, 3674 NL80211_EXT_FEATURE_BEACON_RATE_HT)) 3675 return -EINVAL; 3676 if (count_vht && 3677 !wiphy_ext_feature_isset(&rdev->wiphy, 3678 NL80211_EXT_FEATURE_BEACON_RATE_VHT)) 3679 return -EINVAL; 3680 3681 return 0; 3682 } 3683 3684 static int nl80211_parse_beacon(struct nlattr *attrs[], 3685 struct cfg80211_beacon_data *bcn) 3686 { 3687 bool haveinfo = false; 3688 3689 if (!is_valid_ie_attr(attrs[NL80211_ATTR_BEACON_TAIL]) || 3690 !is_valid_ie_attr(attrs[NL80211_ATTR_IE]) || 3691 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_PROBE_RESP]) || 3692 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_ASSOC_RESP])) 3693 return -EINVAL; 3694 3695 memset(bcn, 0, sizeof(*bcn)); 3696 3697 if (attrs[NL80211_ATTR_BEACON_HEAD]) { 3698 bcn->head = nla_data(attrs[NL80211_ATTR_BEACON_HEAD]); 3699 bcn->head_len = nla_len(attrs[NL80211_ATTR_BEACON_HEAD]); 3700 if (!bcn->head_len) 3701 return -EINVAL; 3702 haveinfo = true; 3703 } 3704 3705 if (attrs[NL80211_ATTR_BEACON_TAIL]) { 3706 bcn->tail = nla_data(attrs[NL80211_ATTR_BEACON_TAIL]); 3707 bcn->tail_len = nla_len(attrs[NL80211_ATTR_BEACON_TAIL]); 3708 haveinfo = true; 3709 } 3710 3711 if (!haveinfo) 3712 return -EINVAL; 3713 3714 if (attrs[NL80211_ATTR_IE]) { 3715 bcn->beacon_ies = nla_data(attrs[NL80211_ATTR_IE]); 3716 bcn->beacon_ies_len = nla_len(attrs[NL80211_ATTR_IE]); 3717 } 3718 3719 if (attrs[NL80211_ATTR_IE_PROBE_RESP]) { 3720 bcn->proberesp_ies = 3721 nla_data(attrs[NL80211_ATTR_IE_PROBE_RESP]); 3722 bcn->proberesp_ies_len = 3723 nla_len(attrs[NL80211_ATTR_IE_PROBE_RESP]); 3724 } 3725 3726 if (attrs[NL80211_ATTR_IE_ASSOC_RESP]) { 3727 bcn->assocresp_ies = 3728 nla_data(attrs[NL80211_ATTR_IE_ASSOC_RESP]); 3729 bcn->assocresp_ies_len = 3730 nla_len(attrs[NL80211_ATTR_IE_ASSOC_RESP]); 3731 } 3732 3733 if (attrs[NL80211_ATTR_PROBE_RESP]) { 3734 bcn->probe_resp = nla_data(attrs[NL80211_ATTR_PROBE_RESP]); 3735 bcn->probe_resp_len = nla_len(attrs[NL80211_ATTR_PROBE_RESP]); 3736 } 3737 3738 return 0; 3739 } 3740 3741 static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev, 3742 struct cfg80211_ap_settings *params) 3743 { 3744 struct wireless_dev *wdev; 3745 bool ret = false; 3746 3747 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) { 3748 if (wdev->iftype != NL80211_IFTYPE_AP && 3749 wdev->iftype != NL80211_IFTYPE_P2P_GO) 3750 continue; 3751 3752 if (!wdev->preset_chandef.chan) 3753 continue; 3754 3755 params->chandef = wdev->preset_chandef; 3756 ret = true; 3757 break; 3758 } 3759 3760 return ret; 3761 } 3762 3763 static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev, 3764 enum nl80211_auth_type auth_type, 3765 enum nl80211_commands cmd) 3766 { 3767 if (auth_type > NL80211_AUTHTYPE_MAX) 3768 return false; 3769 3770 switch (cmd) { 3771 case NL80211_CMD_AUTHENTICATE: 3772 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) && 3773 auth_type == NL80211_AUTHTYPE_SAE) 3774 return false; 3775 if (!wiphy_ext_feature_isset(&rdev->wiphy, 3776 NL80211_EXT_FEATURE_FILS_STA) && 3777 (auth_type == NL80211_AUTHTYPE_FILS_SK || 3778 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS || 3779 auth_type == NL80211_AUTHTYPE_FILS_PK)) 3780 return false; 3781 return true; 3782 case NL80211_CMD_CONNECT: 3783 case NL80211_CMD_START_AP: 3784 /* SAE not supported yet */ 3785 if (auth_type == NL80211_AUTHTYPE_SAE) 3786 return false; 3787 /* FILS not supported yet */ 3788 if (auth_type == NL80211_AUTHTYPE_FILS_SK || 3789 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS || 3790 auth_type == NL80211_AUTHTYPE_FILS_PK) 3791 return false; 3792 return true; 3793 default: 3794 return false; 3795 } 3796 } 3797 3798 static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info) 3799 { 3800 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3801 struct net_device *dev = info->user_ptr[1]; 3802 struct wireless_dev *wdev = dev->ieee80211_ptr; 3803 struct cfg80211_ap_settings params; 3804 int err; 3805 3806 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 3807 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3808 return -EOPNOTSUPP; 3809 3810 if (!rdev->ops->start_ap) 3811 return -EOPNOTSUPP; 3812 3813 if (wdev->beacon_interval) 3814 return -EALREADY; 3815 3816 memset(¶ms, 0, sizeof(params)); 3817 3818 /* these are required for START_AP */ 3819 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] || 3820 !info->attrs[NL80211_ATTR_DTIM_PERIOD] || 3821 !info->attrs[NL80211_ATTR_BEACON_HEAD]) 3822 return -EINVAL; 3823 3824 err = nl80211_parse_beacon(info->attrs, ¶ms.beacon); 3825 if (err) 3826 return err; 3827 3828 params.beacon_interval = 3829 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]); 3830 params.dtim_period = 3831 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]); 3832 3833 err = cfg80211_validate_beacon_int(rdev, dev->ieee80211_ptr->iftype, 3834 params.beacon_interval); 3835 if (err) 3836 return err; 3837 3838 /* 3839 * In theory, some of these attributes should be required here 3840 * but since they were not used when the command was originally 3841 * added, keep them optional for old user space programs to let 3842 * them continue to work with drivers that do not need the 3843 * additional information -- drivers must check! 3844 */ 3845 if (info->attrs[NL80211_ATTR_SSID]) { 3846 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 3847 params.ssid_len = 3848 nla_len(info->attrs[NL80211_ATTR_SSID]); 3849 if (params.ssid_len == 0 || 3850 params.ssid_len > IEEE80211_MAX_SSID_LEN) 3851 return -EINVAL; 3852 } 3853 3854 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) { 3855 params.hidden_ssid = nla_get_u32( 3856 info->attrs[NL80211_ATTR_HIDDEN_SSID]); 3857 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE && 3858 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN && 3859 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS) 3860 return -EINVAL; 3861 } 3862 3863 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY]; 3864 3865 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) { 3866 params.auth_type = nla_get_u32( 3867 info->attrs[NL80211_ATTR_AUTH_TYPE]); 3868 if (!nl80211_valid_auth_type(rdev, params.auth_type, 3869 NL80211_CMD_START_AP)) 3870 return -EINVAL; 3871 } else 3872 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC; 3873 3874 err = nl80211_crypto_settings(rdev, info, ¶ms.crypto, 3875 NL80211_MAX_NR_CIPHER_SUITES); 3876 if (err) 3877 return err; 3878 3879 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) { 3880 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER)) 3881 return -EOPNOTSUPP; 3882 params.inactivity_timeout = nla_get_u16( 3883 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]); 3884 } 3885 3886 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) { 3887 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3888 return -EINVAL; 3889 params.p2p_ctwindow = 3890 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]); 3891 if (params.p2p_ctwindow > 127) 3892 return -EINVAL; 3893 if (params.p2p_ctwindow != 0 && 3894 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN)) 3895 return -EINVAL; 3896 } 3897 3898 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) { 3899 u8 tmp; 3900 3901 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3902 return -EINVAL; 3903 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]); 3904 if (tmp > 1) 3905 return -EINVAL; 3906 params.p2p_opp_ps = tmp; 3907 if (params.p2p_opp_ps != 0 && 3908 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS)) 3909 return -EINVAL; 3910 } 3911 3912 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 3913 err = nl80211_parse_chandef(rdev, info, ¶ms.chandef); 3914 if (err) 3915 return err; 3916 } else if (wdev->preset_chandef.chan) { 3917 params.chandef = wdev->preset_chandef; 3918 } else if (!nl80211_get_ap_channel(rdev, ¶ms)) 3919 return -EINVAL; 3920 3921 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, ¶ms.chandef, 3922 wdev->iftype)) 3923 return -EINVAL; 3924 3925 if (info->attrs[NL80211_ATTR_TX_RATES]) { 3926 err = nl80211_parse_tx_bitrate_mask(info, ¶ms.beacon_rate); 3927 if (err) 3928 return err; 3929 3930 err = validate_beacon_tx_rate(rdev, params.chandef.chan->band, 3931 ¶ms.beacon_rate); 3932 if (err) 3933 return err; 3934 } 3935 3936 if (info->attrs[NL80211_ATTR_SMPS_MODE]) { 3937 params.smps_mode = 3938 nla_get_u8(info->attrs[NL80211_ATTR_SMPS_MODE]); 3939 switch (params.smps_mode) { 3940 case NL80211_SMPS_OFF: 3941 break; 3942 case NL80211_SMPS_STATIC: 3943 if (!(rdev->wiphy.features & 3944 NL80211_FEATURE_STATIC_SMPS)) 3945 return -EINVAL; 3946 break; 3947 case NL80211_SMPS_DYNAMIC: 3948 if (!(rdev->wiphy.features & 3949 NL80211_FEATURE_DYNAMIC_SMPS)) 3950 return -EINVAL; 3951 break; 3952 default: 3953 return -EINVAL; 3954 } 3955 } else { 3956 params.smps_mode = NL80211_SMPS_OFF; 3957 } 3958 3959 params.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]); 3960 if (params.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ]) 3961 return -EOPNOTSUPP; 3962 3963 if (info->attrs[NL80211_ATTR_ACL_POLICY]) { 3964 params.acl = parse_acl_data(&rdev->wiphy, info); 3965 if (IS_ERR(params.acl)) 3966 return PTR_ERR(params.acl); 3967 } 3968 3969 wdev_lock(wdev); 3970 err = rdev_start_ap(rdev, dev, ¶ms); 3971 if (!err) { 3972 wdev->preset_chandef = params.chandef; 3973 wdev->beacon_interval = params.beacon_interval; 3974 wdev->chandef = params.chandef; 3975 wdev->ssid_len = params.ssid_len; 3976 memcpy(wdev->ssid, params.ssid, wdev->ssid_len); 3977 } 3978 wdev_unlock(wdev); 3979 3980 kfree(params.acl); 3981 3982 return err; 3983 } 3984 3985 static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info) 3986 { 3987 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3988 struct net_device *dev = info->user_ptr[1]; 3989 struct wireless_dev *wdev = dev->ieee80211_ptr; 3990 struct cfg80211_beacon_data params; 3991 int err; 3992 3993 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 3994 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3995 return -EOPNOTSUPP; 3996 3997 if (!rdev->ops->change_beacon) 3998 return -EOPNOTSUPP; 3999 4000 if (!wdev->beacon_interval) 4001 return -EINVAL; 4002 4003 err = nl80211_parse_beacon(info->attrs, ¶ms); 4004 if (err) 4005 return err; 4006 4007 wdev_lock(wdev); 4008 err = rdev_change_beacon(rdev, dev, ¶ms); 4009 wdev_unlock(wdev); 4010 4011 return err; 4012 } 4013 4014 static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info) 4015 { 4016 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 4017 struct net_device *dev = info->user_ptr[1]; 4018 4019 return cfg80211_stop_ap(rdev, dev, false); 4020 } 4021 4022 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = { 4023 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG }, 4024 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG }, 4025 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG }, 4026 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG }, 4027 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG }, 4028 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG }, 4029 }; 4030 4031 static int parse_station_flags(struct genl_info *info, 4032 enum nl80211_iftype iftype, 4033 struct station_parameters *params) 4034 { 4035 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1]; 4036 struct nlattr *nla; 4037 int flag; 4038 4039 /* 4040 * Try parsing the new attribute first so userspace 4041 * can specify both for older kernels. 4042 */ 4043 nla = info->attrs[NL80211_ATTR_STA_FLAGS2]; 4044 if (nla) { 4045 struct nl80211_sta_flag_update *sta_flags; 4046 4047 sta_flags = nla_data(nla); 4048 params->sta_flags_mask = sta_flags->mask; 4049 params->sta_flags_set = sta_flags->set; 4050 params->sta_flags_set &= params->sta_flags_mask; 4051 if ((params->sta_flags_mask | 4052 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID)) 4053 return -EINVAL; 4054 return 0; 4055 } 4056 4057 /* if present, parse the old attribute */ 4058 4059 nla = info->attrs[NL80211_ATTR_STA_FLAGS]; 4060 if (!nla) 4061 return 0; 4062 4063 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX, 4064 nla, sta_flags_policy)) 4065 return -EINVAL; 4066 4067 /* 4068 * Only allow certain flags for interface types so that 4069 * other attributes are silently ignored. Remember that 4070 * this is backward compatibility code with old userspace 4071 * and shouldn't be hit in other cases anyway. 4072 */ 4073 switch (iftype) { 4074 case NL80211_IFTYPE_AP: 4075 case NL80211_IFTYPE_AP_VLAN: 4076 case NL80211_IFTYPE_P2P_GO: 4077 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) | 4078 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) | 4079 BIT(NL80211_STA_FLAG_WME) | 4080 BIT(NL80211_STA_FLAG_MFP); 4081 break; 4082 case NL80211_IFTYPE_P2P_CLIENT: 4083 case NL80211_IFTYPE_STATION: 4084 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) | 4085 BIT(NL80211_STA_FLAG_TDLS_PEER); 4086 break; 4087 case NL80211_IFTYPE_MESH_POINT: 4088 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4089 BIT(NL80211_STA_FLAG_MFP) | 4090 BIT(NL80211_STA_FLAG_AUTHORIZED); 4091 default: 4092 return -EINVAL; 4093 } 4094 4095 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) { 4096 if (flags[flag]) { 4097 params->sta_flags_set |= (1<<flag); 4098 4099 /* no longer support new API additions in old API */ 4100 if (flag > NL80211_STA_FLAG_MAX_OLD_API) 4101 return -EINVAL; 4102 } 4103 } 4104 4105 return 0; 4106 } 4107 4108 static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info, 4109 int attr) 4110 { 4111 struct nlattr *rate; 4112 u32 bitrate; 4113 u16 bitrate_compat; 4114 enum nl80211_attrs rate_flg; 4115 4116 rate = nla_nest_start(msg, attr); 4117 if (!rate) 4118 return false; 4119 4120 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */ 4121 bitrate = cfg80211_calculate_bitrate(info); 4122 /* report 16-bit bitrate only if we can */ 4123 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0; 4124 if (bitrate > 0 && 4125 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate)) 4126 return false; 4127 if (bitrate_compat > 0 && 4128 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat)) 4129 return false; 4130 4131 switch (info->bw) { 4132 case RATE_INFO_BW_5: 4133 rate_flg = NL80211_RATE_INFO_5_MHZ_WIDTH; 4134 break; 4135 case RATE_INFO_BW_10: 4136 rate_flg = NL80211_RATE_INFO_10_MHZ_WIDTH; 4137 break; 4138 default: 4139 WARN_ON(1); 4140 /* fall through */ 4141 case RATE_INFO_BW_20: 4142 rate_flg = 0; 4143 break; 4144 case RATE_INFO_BW_40: 4145 rate_flg = NL80211_RATE_INFO_40_MHZ_WIDTH; 4146 break; 4147 case RATE_INFO_BW_80: 4148 rate_flg = NL80211_RATE_INFO_80_MHZ_WIDTH; 4149 break; 4150 case RATE_INFO_BW_160: 4151 rate_flg = NL80211_RATE_INFO_160_MHZ_WIDTH; 4152 break; 4153 } 4154 4155 if (rate_flg && nla_put_flag(msg, rate_flg)) 4156 return false; 4157 4158 if (info->flags & RATE_INFO_FLAGS_MCS) { 4159 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs)) 4160 return false; 4161 if (info->flags & RATE_INFO_FLAGS_SHORT_GI && 4162 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI)) 4163 return false; 4164 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) { 4165 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs)) 4166 return false; 4167 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss)) 4168 return false; 4169 if (info->flags & RATE_INFO_FLAGS_SHORT_GI && 4170 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI)) 4171 return false; 4172 } 4173 4174 nla_nest_end(msg, rate); 4175 return true; 4176 } 4177 4178 static bool nl80211_put_signal(struct sk_buff *msg, u8 mask, s8 *signal, 4179 int id) 4180 { 4181 void *attr; 4182 int i = 0; 4183 4184 if (!mask) 4185 return true; 4186 4187 attr = nla_nest_start(msg, id); 4188 if (!attr) 4189 return false; 4190 4191 for (i = 0; i < IEEE80211_MAX_CHAINS; i++) { 4192 if (!(mask & BIT(i))) 4193 continue; 4194 4195 if (nla_put_u8(msg, i, signal[i])) 4196 return false; 4197 } 4198 4199 nla_nest_end(msg, attr); 4200 4201 return true; 4202 } 4203 4204 static int nl80211_send_station(struct sk_buff *msg, u32 cmd, u32 portid, 4205 u32 seq, int flags, 4206 struct cfg80211_registered_device *rdev, 4207 struct net_device *dev, 4208 const u8 *mac_addr, struct station_info *sinfo) 4209 { 4210 void *hdr; 4211 struct nlattr *sinfoattr, *bss_param; 4212 4213 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 4214 if (!hdr) 4215 return -1; 4216 4217 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 4218 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) || 4219 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation)) 4220 goto nla_put_failure; 4221 4222 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO); 4223 if (!sinfoattr) 4224 goto nla_put_failure; 4225 4226 #define PUT_SINFO(attr, memb, type) do { \ 4227 BUILD_BUG_ON(sizeof(type) == sizeof(u64)); \ 4228 if (sinfo->filled & (1ULL << NL80211_STA_INFO_ ## attr) && \ 4229 nla_put_ ## type(msg, NL80211_STA_INFO_ ## attr, \ 4230 sinfo->memb)) \ 4231 goto nla_put_failure; \ 4232 } while (0) 4233 #define PUT_SINFO_U64(attr, memb) do { \ 4234 if (sinfo->filled & (1ULL << NL80211_STA_INFO_ ## attr) && \ 4235 nla_put_u64_64bit(msg, NL80211_STA_INFO_ ## attr, \ 4236 sinfo->memb, NL80211_STA_INFO_PAD)) \ 4237 goto nla_put_failure; \ 4238 } while (0) 4239 4240 PUT_SINFO(CONNECTED_TIME, connected_time, u32); 4241 PUT_SINFO(INACTIVE_TIME, inactive_time, u32); 4242 4243 if (sinfo->filled & (BIT(NL80211_STA_INFO_RX_BYTES) | 4244 BIT(NL80211_STA_INFO_RX_BYTES64)) && 4245 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES, 4246 (u32)sinfo->rx_bytes)) 4247 goto nla_put_failure; 4248 4249 if (sinfo->filled & (BIT(NL80211_STA_INFO_TX_BYTES) | 4250 BIT(NL80211_STA_INFO_TX_BYTES64)) && 4251 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES, 4252 (u32)sinfo->tx_bytes)) 4253 goto nla_put_failure; 4254 4255 PUT_SINFO_U64(RX_BYTES64, rx_bytes); 4256 PUT_SINFO_U64(TX_BYTES64, tx_bytes); 4257 PUT_SINFO(LLID, llid, u16); 4258 PUT_SINFO(PLID, plid, u16); 4259 PUT_SINFO(PLINK_STATE, plink_state, u8); 4260 PUT_SINFO_U64(RX_DURATION, rx_duration); 4261 4262 switch (rdev->wiphy.signal_type) { 4263 case CFG80211_SIGNAL_TYPE_MBM: 4264 PUT_SINFO(SIGNAL, signal, u8); 4265 PUT_SINFO(SIGNAL_AVG, signal_avg, u8); 4266 break; 4267 default: 4268 break; 4269 } 4270 if (sinfo->filled & BIT(NL80211_STA_INFO_CHAIN_SIGNAL)) { 4271 if (!nl80211_put_signal(msg, sinfo->chains, 4272 sinfo->chain_signal, 4273 NL80211_STA_INFO_CHAIN_SIGNAL)) 4274 goto nla_put_failure; 4275 } 4276 if (sinfo->filled & BIT(NL80211_STA_INFO_CHAIN_SIGNAL_AVG)) { 4277 if (!nl80211_put_signal(msg, sinfo->chains, 4278 sinfo->chain_signal_avg, 4279 NL80211_STA_INFO_CHAIN_SIGNAL_AVG)) 4280 goto nla_put_failure; 4281 } 4282 if (sinfo->filled & BIT(NL80211_STA_INFO_TX_BITRATE)) { 4283 if (!nl80211_put_sta_rate(msg, &sinfo->txrate, 4284 NL80211_STA_INFO_TX_BITRATE)) 4285 goto nla_put_failure; 4286 } 4287 if (sinfo->filled & BIT(NL80211_STA_INFO_RX_BITRATE)) { 4288 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate, 4289 NL80211_STA_INFO_RX_BITRATE)) 4290 goto nla_put_failure; 4291 } 4292 4293 PUT_SINFO(RX_PACKETS, rx_packets, u32); 4294 PUT_SINFO(TX_PACKETS, tx_packets, u32); 4295 PUT_SINFO(TX_RETRIES, tx_retries, u32); 4296 PUT_SINFO(TX_FAILED, tx_failed, u32); 4297 PUT_SINFO(EXPECTED_THROUGHPUT, expected_throughput, u32); 4298 PUT_SINFO(BEACON_LOSS, beacon_loss_count, u32); 4299 PUT_SINFO(LOCAL_PM, local_pm, u32); 4300 PUT_SINFO(PEER_PM, peer_pm, u32); 4301 PUT_SINFO(NONPEER_PM, nonpeer_pm, u32); 4302 4303 if (sinfo->filled & BIT(NL80211_STA_INFO_BSS_PARAM)) { 4304 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM); 4305 if (!bss_param) 4306 goto nla_put_failure; 4307 4308 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) && 4309 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) || 4310 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) && 4311 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) || 4312 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) && 4313 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) || 4314 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD, 4315 sinfo->bss_param.dtim_period) || 4316 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL, 4317 sinfo->bss_param.beacon_interval)) 4318 goto nla_put_failure; 4319 4320 nla_nest_end(msg, bss_param); 4321 } 4322 if ((sinfo->filled & BIT(NL80211_STA_INFO_STA_FLAGS)) && 4323 nla_put(msg, NL80211_STA_INFO_STA_FLAGS, 4324 sizeof(struct nl80211_sta_flag_update), 4325 &sinfo->sta_flags)) 4326 goto nla_put_failure; 4327 4328 PUT_SINFO_U64(T_OFFSET, t_offset); 4329 PUT_SINFO_U64(RX_DROP_MISC, rx_dropped_misc); 4330 PUT_SINFO_U64(BEACON_RX, rx_beacon); 4331 PUT_SINFO(BEACON_SIGNAL_AVG, rx_beacon_signal_avg, u8); 4332 4333 #undef PUT_SINFO 4334 #undef PUT_SINFO_U64 4335 4336 if (sinfo->filled & BIT(NL80211_STA_INFO_TID_STATS)) { 4337 struct nlattr *tidsattr; 4338 int tid; 4339 4340 tidsattr = nla_nest_start(msg, NL80211_STA_INFO_TID_STATS); 4341 if (!tidsattr) 4342 goto nla_put_failure; 4343 4344 for (tid = 0; tid < IEEE80211_NUM_TIDS + 1; tid++) { 4345 struct cfg80211_tid_stats *tidstats; 4346 struct nlattr *tidattr; 4347 4348 tidstats = &sinfo->pertid[tid]; 4349 4350 if (!tidstats->filled) 4351 continue; 4352 4353 tidattr = nla_nest_start(msg, tid + 1); 4354 if (!tidattr) 4355 goto nla_put_failure; 4356 4357 #define PUT_TIDVAL_U64(attr, memb) do { \ 4358 if (tidstats->filled & BIT(NL80211_TID_STATS_ ## attr) && \ 4359 nla_put_u64_64bit(msg, NL80211_TID_STATS_ ## attr, \ 4360 tidstats->memb, NL80211_TID_STATS_PAD)) \ 4361 goto nla_put_failure; \ 4362 } while (0) 4363 4364 PUT_TIDVAL_U64(RX_MSDU, rx_msdu); 4365 PUT_TIDVAL_U64(TX_MSDU, tx_msdu); 4366 PUT_TIDVAL_U64(TX_MSDU_RETRIES, tx_msdu_retries); 4367 PUT_TIDVAL_U64(TX_MSDU_FAILED, tx_msdu_failed); 4368 4369 #undef PUT_TIDVAL_U64 4370 nla_nest_end(msg, tidattr); 4371 } 4372 4373 nla_nest_end(msg, tidsattr); 4374 } 4375 4376 nla_nest_end(msg, sinfoattr); 4377 4378 if (sinfo->assoc_req_ies_len && 4379 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len, 4380 sinfo->assoc_req_ies)) 4381 goto nla_put_failure; 4382 4383 genlmsg_end(msg, hdr); 4384 return 0; 4385 4386 nla_put_failure: 4387 genlmsg_cancel(msg, hdr); 4388 return -EMSGSIZE; 4389 } 4390 4391 static int nl80211_dump_station(struct sk_buff *skb, 4392 struct netlink_callback *cb) 4393 { 4394 struct station_info sinfo; 4395 struct cfg80211_registered_device *rdev; 4396 struct wireless_dev *wdev; 4397 u8 mac_addr[ETH_ALEN]; 4398 int sta_idx = cb->args[2]; 4399 int err; 4400 4401 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 4402 if (err) 4403 return err; 4404 4405 if (!wdev->netdev) { 4406 err = -EINVAL; 4407 goto out_err; 4408 } 4409 4410 if (!rdev->ops->dump_station) { 4411 err = -EOPNOTSUPP; 4412 goto out_err; 4413 } 4414 4415 while (1) { 4416 memset(&sinfo, 0, sizeof(sinfo)); 4417 err = rdev_dump_station(rdev, wdev->netdev, sta_idx, 4418 mac_addr, &sinfo); 4419 if (err == -ENOENT) 4420 break; 4421 if (err) 4422 goto out_err; 4423 4424 if (nl80211_send_station(skb, NL80211_CMD_NEW_STATION, 4425 NETLINK_CB(cb->skb).portid, 4426 cb->nlh->nlmsg_seq, NLM_F_MULTI, 4427 rdev, wdev->netdev, mac_addr, 4428 &sinfo) < 0) 4429 goto out; 4430 4431 sta_idx++; 4432 } 4433 4434 out: 4435 cb->args[2] = sta_idx; 4436 err = skb->len; 4437 out_err: 4438 nl80211_finish_wdev_dump(rdev); 4439 4440 return err; 4441 } 4442 4443 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info) 4444 { 4445 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 4446 struct net_device *dev = info->user_ptr[1]; 4447 struct station_info sinfo; 4448 struct sk_buff *msg; 4449 u8 *mac_addr = NULL; 4450 int err; 4451 4452 memset(&sinfo, 0, sizeof(sinfo)); 4453 4454 if (!info->attrs[NL80211_ATTR_MAC]) 4455 return -EINVAL; 4456 4457 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 4458 4459 if (!rdev->ops->get_station) 4460 return -EOPNOTSUPP; 4461 4462 err = rdev_get_station(rdev, dev, mac_addr, &sinfo); 4463 if (err) 4464 return err; 4465 4466 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 4467 if (!msg) 4468 return -ENOMEM; 4469 4470 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION, 4471 info->snd_portid, info->snd_seq, 0, 4472 rdev, dev, mac_addr, &sinfo) < 0) { 4473 nlmsg_free(msg); 4474 return -ENOBUFS; 4475 } 4476 4477 return genlmsg_reply(msg, info); 4478 } 4479 4480 int cfg80211_check_station_change(struct wiphy *wiphy, 4481 struct station_parameters *params, 4482 enum cfg80211_station_type statype) 4483 { 4484 if (params->listen_interval != -1 && 4485 statype != CFG80211_STA_AP_CLIENT_UNASSOC) 4486 return -EINVAL; 4487 4488 if (params->support_p2p_ps != -1 && 4489 statype != CFG80211_STA_AP_CLIENT_UNASSOC) 4490 return -EINVAL; 4491 4492 if (params->aid && 4493 !(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) && 4494 statype != CFG80211_STA_AP_CLIENT_UNASSOC) 4495 return -EINVAL; 4496 4497 /* When you run into this, adjust the code below for the new flag */ 4498 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7); 4499 4500 switch (statype) { 4501 case CFG80211_STA_MESH_PEER_KERNEL: 4502 case CFG80211_STA_MESH_PEER_USER: 4503 /* 4504 * No ignoring the TDLS flag here -- the userspace mesh 4505 * code doesn't have the bug of including TDLS in the 4506 * mask everywhere. 4507 */ 4508 if (params->sta_flags_mask & 4509 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4510 BIT(NL80211_STA_FLAG_MFP) | 4511 BIT(NL80211_STA_FLAG_AUTHORIZED))) 4512 return -EINVAL; 4513 break; 4514 case CFG80211_STA_TDLS_PEER_SETUP: 4515 case CFG80211_STA_TDLS_PEER_ACTIVE: 4516 if (!(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))) 4517 return -EINVAL; 4518 /* ignore since it can't change */ 4519 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER); 4520 break; 4521 default: 4522 /* disallow mesh-specific things */ 4523 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION) 4524 return -EINVAL; 4525 if (params->local_pm) 4526 return -EINVAL; 4527 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE) 4528 return -EINVAL; 4529 } 4530 4531 if (statype != CFG80211_STA_TDLS_PEER_SETUP && 4532 statype != CFG80211_STA_TDLS_PEER_ACTIVE) { 4533 /* TDLS can't be set, ... */ 4534 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) 4535 return -EINVAL; 4536 /* 4537 * ... but don't bother the driver with it. This works around 4538 * a hostapd/wpa_supplicant issue -- it always includes the 4539 * TLDS_PEER flag in the mask even for AP mode. 4540 */ 4541 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER); 4542 } 4543 4544 if (statype != CFG80211_STA_TDLS_PEER_SETUP && 4545 statype != CFG80211_STA_AP_CLIENT_UNASSOC) { 4546 /* reject other things that can't change */ 4547 if (params->sta_modify_mask & STATION_PARAM_APPLY_UAPSD) 4548 return -EINVAL; 4549 if (params->sta_modify_mask & STATION_PARAM_APPLY_CAPABILITY) 4550 return -EINVAL; 4551 if (params->supported_rates) 4552 return -EINVAL; 4553 if (params->ext_capab || params->ht_capa || params->vht_capa) 4554 return -EINVAL; 4555 } 4556 4557 if (statype != CFG80211_STA_AP_CLIENT && 4558 statype != CFG80211_STA_AP_CLIENT_UNASSOC) { 4559 if (params->vlan) 4560 return -EINVAL; 4561 } 4562 4563 switch (statype) { 4564 case CFG80211_STA_AP_MLME_CLIENT: 4565 /* Use this only for authorizing/unauthorizing a station */ 4566 if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED))) 4567 return -EOPNOTSUPP; 4568 break; 4569 case CFG80211_STA_AP_CLIENT: 4570 case CFG80211_STA_AP_CLIENT_UNASSOC: 4571 /* accept only the listed bits */ 4572 if (params->sta_flags_mask & 4573 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) | 4574 BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4575 BIT(NL80211_STA_FLAG_ASSOCIATED) | 4576 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) | 4577 BIT(NL80211_STA_FLAG_WME) | 4578 BIT(NL80211_STA_FLAG_MFP))) 4579 return -EINVAL; 4580 4581 /* but authenticated/associated only if driver handles it */ 4582 if (!(wiphy->features & NL80211_FEATURE_FULL_AP_CLIENT_STATE) && 4583 params->sta_flags_mask & 4584 (BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4585 BIT(NL80211_STA_FLAG_ASSOCIATED))) 4586 return -EINVAL; 4587 break; 4588 case CFG80211_STA_IBSS: 4589 case CFG80211_STA_AP_STA: 4590 /* reject any changes other than AUTHORIZED */ 4591 if (params->sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED)) 4592 return -EINVAL; 4593 break; 4594 case CFG80211_STA_TDLS_PEER_SETUP: 4595 /* reject any changes other than AUTHORIZED or WME */ 4596 if (params->sta_flags_mask & ~(BIT(NL80211_STA_FLAG_AUTHORIZED) | 4597 BIT(NL80211_STA_FLAG_WME))) 4598 return -EINVAL; 4599 /* force (at least) rates when authorizing */ 4600 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED) && 4601 !params->supported_rates) 4602 return -EINVAL; 4603 break; 4604 case CFG80211_STA_TDLS_PEER_ACTIVE: 4605 /* reject any changes */ 4606 return -EINVAL; 4607 case CFG80211_STA_MESH_PEER_KERNEL: 4608 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE) 4609 return -EINVAL; 4610 break; 4611 case CFG80211_STA_MESH_PEER_USER: 4612 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION && 4613 params->plink_action != NL80211_PLINK_ACTION_BLOCK) 4614 return -EINVAL; 4615 break; 4616 } 4617 4618 /* 4619 * Older kernel versions ignored this attribute entirely, so don't 4620 * reject attempts to update it but mark it as unused instead so the 4621 * driver won't look at the data. 4622 */ 4623 if (statype != CFG80211_STA_AP_CLIENT_UNASSOC && 4624 statype != CFG80211_STA_TDLS_PEER_SETUP) 4625 params->opmode_notif_used = false; 4626 4627 return 0; 4628 } 4629 EXPORT_SYMBOL(cfg80211_check_station_change); 4630 4631 /* 4632 * Get vlan interface making sure it is running and on the right wiphy. 4633 */ 4634 static struct net_device *get_vlan(struct genl_info *info, 4635 struct cfg80211_registered_device *rdev) 4636 { 4637 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN]; 4638 struct net_device *v; 4639 int ret; 4640 4641 if (!vlanattr) 4642 return NULL; 4643 4644 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr)); 4645 if (!v) 4646 return ERR_PTR(-ENODEV); 4647 4648 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) { 4649 ret = -EINVAL; 4650 goto error; 4651 } 4652 4653 if (v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN && 4654 v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 4655 v->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) { 4656 ret = -EINVAL; 4657 goto error; 4658 } 4659 4660 if (!netif_running(v)) { 4661 ret = -ENETDOWN; 4662 goto error; 4663 } 4664 4665 return v; 4666 error: 4667 dev_put(v); 4668 return ERR_PTR(ret); 4669 } 4670 4671 static const struct nla_policy 4672 nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] = { 4673 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 }, 4674 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 }, 4675 }; 4676 4677 static int nl80211_parse_sta_wme(struct genl_info *info, 4678 struct station_parameters *params) 4679 { 4680 struct nlattr *tb[NL80211_STA_WME_MAX + 1]; 4681 struct nlattr *nla; 4682 int err; 4683 4684 /* parse WME attributes if present */ 4685 if (!info->attrs[NL80211_ATTR_STA_WME]) 4686 return 0; 4687 4688 nla = info->attrs[NL80211_ATTR_STA_WME]; 4689 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla, 4690 nl80211_sta_wme_policy); 4691 if (err) 4692 return err; 4693 4694 if (tb[NL80211_STA_WME_UAPSD_QUEUES]) 4695 params->uapsd_queues = nla_get_u8( 4696 tb[NL80211_STA_WME_UAPSD_QUEUES]); 4697 if (params->uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK) 4698 return -EINVAL; 4699 4700 if (tb[NL80211_STA_WME_MAX_SP]) 4701 params->max_sp = nla_get_u8(tb[NL80211_STA_WME_MAX_SP]); 4702 4703 if (params->max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK) 4704 return -EINVAL; 4705 4706 params->sta_modify_mask |= STATION_PARAM_APPLY_UAPSD; 4707 4708 return 0; 4709 } 4710 4711 static int nl80211_parse_sta_channel_info(struct genl_info *info, 4712 struct station_parameters *params) 4713 { 4714 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]) { 4715 params->supported_channels = 4716 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]); 4717 params->supported_channels_len = 4718 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]); 4719 /* 4720 * Need to include at least one (first channel, number of 4721 * channels) tuple for each subband, and must have proper 4722 * tuples for the rest of the data as well. 4723 */ 4724 if (params->supported_channels_len < 2) 4725 return -EINVAL; 4726 if (params->supported_channels_len % 2) 4727 return -EINVAL; 4728 } 4729 4730 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]) { 4731 params->supported_oper_classes = 4732 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]); 4733 params->supported_oper_classes_len = 4734 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]); 4735 /* 4736 * The value of the Length field of the Supported Operating 4737 * Classes element is between 2 and 253. 4738 */ 4739 if (params->supported_oper_classes_len < 2 || 4740 params->supported_oper_classes_len > 253) 4741 return -EINVAL; 4742 } 4743 return 0; 4744 } 4745 4746 static int nl80211_set_station_tdls(struct genl_info *info, 4747 struct station_parameters *params) 4748 { 4749 int err; 4750 /* Dummy STA entry gets updated once the peer capabilities are known */ 4751 if (info->attrs[NL80211_ATTR_PEER_AID]) 4752 params->aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]); 4753 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) 4754 params->ht_capa = 4755 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]); 4756 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) 4757 params->vht_capa = 4758 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]); 4759 4760 err = nl80211_parse_sta_channel_info(info, params); 4761 if (err) 4762 return err; 4763 4764 return nl80211_parse_sta_wme(info, params); 4765 } 4766 4767 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info) 4768 { 4769 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 4770 struct net_device *dev = info->user_ptr[1]; 4771 struct station_parameters params; 4772 u8 *mac_addr; 4773 int err; 4774 4775 memset(¶ms, 0, sizeof(params)); 4776 4777 if (!rdev->ops->change_station) 4778 return -EOPNOTSUPP; 4779 4780 /* 4781 * AID and listen_interval properties can be set only for unassociated 4782 * station. Include these parameters here and will check them in 4783 * cfg80211_check_station_change(). 4784 */ 4785 if (info->attrs[NL80211_ATTR_STA_AID]) 4786 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]); 4787 4788 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]) 4789 params.listen_interval = 4790 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]); 4791 else 4792 params.listen_interval = -1; 4793 4794 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]) { 4795 u8 tmp; 4796 4797 tmp = nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]); 4798 if (tmp >= NUM_NL80211_P2P_PS_STATUS) 4799 return -EINVAL; 4800 4801 params.support_p2p_ps = tmp; 4802 } else { 4803 params.support_p2p_ps = -1; 4804 } 4805 4806 if (!info->attrs[NL80211_ATTR_MAC]) 4807 return -EINVAL; 4808 4809 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 4810 4811 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) { 4812 params.supported_rates = 4813 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]); 4814 params.supported_rates_len = 4815 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]); 4816 } 4817 4818 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) { 4819 params.capability = 4820 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]); 4821 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY; 4822 } 4823 4824 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) { 4825 params.ext_capab = 4826 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]); 4827 params.ext_capab_len = 4828 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]); 4829 } 4830 4831 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, ¶ms)) 4832 return -EINVAL; 4833 4834 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) { 4835 params.plink_action = 4836 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]); 4837 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS) 4838 return -EINVAL; 4839 } 4840 4841 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE]) { 4842 params.plink_state = 4843 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]); 4844 if (params.plink_state >= NUM_NL80211_PLINK_STATES) 4845 return -EINVAL; 4846 if (info->attrs[NL80211_ATTR_MESH_PEER_AID]) { 4847 params.peer_aid = nla_get_u16( 4848 info->attrs[NL80211_ATTR_MESH_PEER_AID]); 4849 if (params.peer_aid > IEEE80211_MAX_AID) 4850 return -EINVAL; 4851 } 4852 params.sta_modify_mask |= STATION_PARAM_APPLY_PLINK_STATE; 4853 } 4854 4855 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]) { 4856 enum nl80211_mesh_power_mode pm = nla_get_u32( 4857 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]); 4858 4859 if (pm <= NL80211_MESH_POWER_UNKNOWN || 4860 pm > NL80211_MESH_POWER_MAX) 4861 return -EINVAL; 4862 4863 params.local_pm = pm; 4864 } 4865 4866 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) { 4867 params.opmode_notif_used = true; 4868 params.opmode_notif = 4869 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]); 4870 } 4871 4872 /* Include parameters for TDLS peer (will check later) */ 4873 err = nl80211_set_station_tdls(info, ¶ms); 4874 if (err) 4875 return err; 4876 4877 params.vlan = get_vlan(info, rdev); 4878 if (IS_ERR(params.vlan)) 4879 return PTR_ERR(params.vlan); 4880 4881 switch (dev->ieee80211_ptr->iftype) { 4882 case NL80211_IFTYPE_AP: 4883 case NL80211_IFTYPE_AP_VLAN: 4884 case NL80211_IFTYPE_P2P_GO: 4885 case NL80211_IFTYPE_P2P_CLIENT: 4886 case NL80211_IFTYPE_STATION: 4887 case NL80211_IFTYPE_ADHOC: 4888 case NL80211_IFTYPE_MESH_POINT: 4889 break; 4890 default: 4891 err = -EOPNOTSUPP; 4892 goto out_put_vlan; 4893 } 4894 4895 /* driver will call cfg80211_check_station_change() */ 4896 err = rdev_change_station(rdev, dev, mac_addr, ¶ms); 4897 4898 out_put_vlan: 4899 if (params.vlan) 4900 dev_put(params.vlan); 4901 4902 return err; 4903 } 4904 4905 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info) 4906 { 4907 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 4908 int err; 4909 struct net_device *dev = info->user_ptr[1]; 4910 struct station_parameters params; 4911 u8 *mac_addr = NULL; 4912 u32 auth_assoc = BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4913 BIT(NL80211_STA_FLAG_ASSOCIATED); 4914 4915 memset(¶ms, 0, sizeof(params)); 4916 4917 if (!rdev->ops->add_station) 4918 return -EOPNOTSUPP; 4919 4920 if (!info->attrs[NL80211_ATTR_MAC]) 4921 return -EINVAL; 4922 4923 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]) 4924 return -EINVAL; 4925 4926 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) 4927 return -EINVAL; 4928 4929 if (!info->attrs[NL80211_ATTR_STA_AID] && 4930 !info->attrs[NL80211_ATTR_PEER_AID]) 4931 return -EINVAL; 4932 4933 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 4934 params.supported_rates = 4935 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]); 4936 params.supported_rates_len = 4937 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]); 4938 params.listen_interval = 4939 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]); 4940 4941 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]) { 4942 u8 tmp; 4943 4944 tmp = nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]); 4945 if (tmp >= NUM_NL80211_P2P_PS_STATUS) 4946 return -EINVAL; 4947 4948 params.support_p2p_ps = tmp; 4949 } else { 4950 /* 4951 * if not specified, assume it's supported for P2P GO interface, 4952 * and is NOT supported for AP interface 4953 */ 4954 params.support_p2p_ps = 4955 dev->ieee80211_ptr->iftype == NL80211_IFTYPE_P2P_GO; 4956 } 4957 4958 if (info->attrs[NL80211_ATTR_PEER_AID]) 4959 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]); 4960 else 4961 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]); 4962 if (!params.aid || params.aid > IEEE80211_MAX_AID) 4963 return -EINVAL; 4964 4965 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) { 4966 params.capability = 4967 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]); 4968 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY; 4969 } 4970 4971 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) { 4972 params.ext_capab = 4973 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]); 4974 params.ext_capab_len = 4975 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]); 4976 } 4977 4978 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) 4979 params.ht_capa = 4980 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]); 4981 4982 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) 4983 params.vht_capa = 4984 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]); 4985 4986 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) { 4987 params.opmode_notif_used = true; 4988 params.opmode_notif = 4989 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]); 4990 } 4991 4992 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) { 4993 params.plink_action = 4994 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]); 4995 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS) 4996 return -EINVAL; 4997 } 4998 4999 err = nl80211_parse_sta_channel_info(info, ¶ms); 5000 if (err) 5001 return err; 5002 5003 err = nl80211_parse_sta_wme(info, ¶ms); 5004 if (err) 5005 return err; 5006 5007 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, ¶ms)) 5008 return -EINVAL; 5009 5010 /* HT/VHT requires QoS, but if we don't have that just ignore HT/VHT 5011 * as userspace might just pass through the capabilities from the IEs 5012 * directly, rather than enforcing this restriction and returning an 5013 * error in this case. 5014 */ 5015 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME))) { 5016 params.ht_capa = NULL; 5017 params.vht_capa = NULL; 5018 } 5019 5020 /* When you run into this, adjust the code below for the new flag */ 5021 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7); 5022 5023 switch (dev->ieee80211_ptr->iftype) { 5024 case NL80211_IFTYPE_AP: 5025 case NL80211_IFTYPE_AP_VLAN: 5026 case NL80211_IFTYPE_P2P_GO: 5027 /* ignore WME attributes if iface/sta is not capable */ 5028 if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) || 5029 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME))) 5030 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD; 5031 5032 /* TDLS peers cannot be added */ 5033 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) || 5034 info->attrs[NL80211_ATTR_PEER_AID]) 5035 return -EINVAL; 5036 /* but don't bother the driver with it */ 5037 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER); 5038 5039 /* allow authenticated/associated only if driver handles it */ 5040 if (!(rdev->wiphy.features & 5041 NL80211_FEATURE_FULL_AP_CLIENT_STATE) && 5042 params.sta_flags_mask & auth_assoc) 5043 return -EINVAL; 5044 5045 /* Older userspace, or userspace wanting to be compatible with 5046 * !NL80211_FEATURE_FULL_AP_CLIENT_STATE, will not set the auth 5047 * and assoc flags in the mask, but assumes the station will be 5048 * added as associated anyway since this was the required driver 5049 * behaviour before NL80211_FEATURE_FULL_AP_CLIENT_STATE was 5050 * introduced. 5051 * In order to not bother drivers with this quirk in the API 5052 * set the flags in both the mask and set for new stations in 5053 * this case. 5054 */ 5055 if (!(params.sta_flags_mask & auth_assoc)) { 5056 params.sta_flags_mask |= auth_assoc; 5057 params.sta_flags_set |= auth_assoc; 5058 } 5059 5060 /* must be last in here for error handling */ 5061 params.vlan = get_vlan(info, rdev); 5062 if (IS_ERR(params.vlan)) 5063 return PTR_ERR(params.vlan); 5064 break; 5065 case NL80211_IFTYPE_MESH_POINT: 5066 /* ignore uAPSD data */ 5067 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD; 5068 5069 /* associated is disallowed */ 5070 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED)) 5071 return -EINVAL; 5072 /* TDLS peers cannot be added */ 5073 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) || 5074 info->attrs[NL80211_ATTR_PEER_AID]) 5075 return -EINVAL; 5076 break; 5077 case NL80211_IFTYPE_STATION: 5078 case NL80211_IFTYPE_P2P_CLIENT: 5079 /* ignore uAPSD data */ 5080 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD; 5081 5082 /* these are disallowed */ 5083 if (params.sta_flags_mask & 5084 (BIT(NL80211_STA_FLAG_ASSOCIATED) | 5085 BIT(NL80211_STA_FLAG_AUTHENTICATED))) 5086 return -EINVAL; 5087 /* Only TDLS peers can be added */ 5088 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))) 5089 return -EINVAL; 5090 /* Can only add if TDLS ... */ 5091 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS)) 5092 return -EOPNOTSUPP; 5093 /* ... with external setup is supported */ 5094 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP)) 5095 return -EOPNOTSUPP; 5096 /* 5097 * Older wpa_supplicant versions always mark the TDLS peer 5098 * as authorized, but it shouldn't yet be. 5099 */ 5100 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_AUTHORIZED); 5101 break; 5102 default: 5103 return -EOPNOTSUPP; 5104 } 5105 5106 /* be aware of params.vlan when changing code here */ 5107 5108 err = rdev_add_station(rdev, dev, mac_addr, ¶ms); 5109 5110 if (params.vlan) 5111 dev_put(params.vlan); 5112 return err; 5113 } 5114 5115 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info) 5116 { 5117 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5118 struct net_device *dev = info->user_ptr[1]; 5119 struct station_del_parameters params; 5120 5121 memset(¶ms, 0, sizeof(params)); 5122 5123 if (info->attrs[NL80211_ATTR_MAC]) 5124 params.mac = nla_data(info->attrs[NL80211_ATTR_MAC]); 5125 5126 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 5127 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN && 5128 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT && 5129 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 5130 return -EINVAL; 5131 5132 if (!rdev->ops->del_station) 5133 return -EOPNOTSUPP; 5134 5135 if (info->attrs[NL80211_ATTR_MGMT_SUBTYPE]) { 5136 params.subtype = 5137 nla_get_u8(info->attrs[NL80211_ATTR_MGMT_SUBTYPE]); 5138 if (params.subtype != IEEE80211_STYPE_DISASSOC >> 4 && 5139 params.subtype != IEEE80211_STYPE_DEAUTH >> 4) 5140 return -EINVAL; 5141 } else { 5142 /* Default to Deauthentication frame */ 5143 params.subtype = IEEE80211_STYPE_DEAUTH >> 4; 5144 } 5145 5146 if (info->attrs[NL80211_ATTR_REASON_CODE]) { 5147 params.reason_code = 5148 nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]); 5149 if (params.reason_code == 0) 5150 return -EINVAL; /* 0 is reserved */ 5151 } else { 5152 /* Default to reason code 2 */ 5153 params.reason_code = WLAN_REASON_PREV_AUTH_NOT_VALID; 5154 } 5155 5156 return rdev_del_station(rdev, dev, ¶ms); 5157 } 5158 5159 static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq, 5160 int flags, struct net_device *dev, 5161 u8 *dst, u8 *next_hop, 5162 struct mpath_info *pinfo) 5163 { 5164 void *hdr; 5165 struct nlattr *pinfoattr; 5166 5167 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_MPATH); 5168 if (!hdr) 5169 return -1; 5170 5171 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 5172 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) || 5173 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) || 5174 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation)) 5175 goto nla_put_failure; 5176 5177 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO); 5178 if (!pinfoattr) 5179 goto nla_put_failure; 5180 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) && 5181 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN, 5182 pinfo->frame_qlen)) 5183 goto nla_put_failure; 5184 if (((pinfo->filled & MPATH_INFO_SN) && 5185 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) || 5186 ((pinfo->filled & MPATH_INFO_METRIC) && 5187 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC, 5188 pinfo->metric)) || 5189 ((pinfo->filled & MPATH_INFO_EXPTIME) && 5190 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME, 5191 pinfo->exptime)) || 5192 ((pinfo->filled & MPATH_INFO_FLAGS) && 5193 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS, 5194 pinfo->flags)) || 5195 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) && 5196 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT, 5197 pinfo->discovery_timeout)) || 5198 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) && 5199 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES, 5200 pinfo->discovery_retries))) 5201 goto nla_put_failure; 5202 5203 nla_nest_end(msg, pinfoattr); 5204 5205 genlmsg_end(msg, hdr); 5206 return 0; 5207 5208 nla_put_failure: 5209 genlmsg_cancel(msg, hdr); 5210 return -EMSGSIZE; 5211 } 5212 5213 static int nl80211_dump_mpath(struct sk_buff *skb, 5214 struct netlink_callback *cb) 5215 { 5216 struct mpath_info pinfo; 5217 struct cfg80211_registered_device *rdev; 5218 struct wireless_dev *wdev; 5219 u8 dst[ETH_ALEN]; 5220 u8 next_hop[ETH_ALEN]; 5221 int path_idx = cb->args[2]; 5222 int err; 5223 5224 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 5225 if (err) 5226 return err; 5227 5228 if (!rdev->ops->dump_mpath) { 5229 err = -EOPNOTSUPP; 5230 goto out_err; 5231 } 5232 5233 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) { 5234 err = -EOPNOTSUPP; 5235 goto out_err; 5236 } 5237 5238 while (1) { 5239 err = rdev_dump_mpath(rdev, wdev->netdev, path_idx, dst, 5240 next_hop, &pinfo); 5241 if (err == -ENOENT) 5242 break; 5243 if (err) 5244 goto out_err; 5245 5246 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid, 5247 cb->nlh->nlmsg_seq, NLM_F_MULTI, 5248 wdev->netdev, dst, next_hop, 5249 &pinfo) < 0) 5250 goto out; 5251 5252 path_idx++; 5253 } 5254 5255 out: 5256 cb->args[2] = path_idx; 5257 err = skb->len; 5258 out_err: 5259 nl80211_finish_wdev_dump(rdev); 5260 return err; 5261 } 5262 5263 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info) 5264 { 5265 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5266 int err; 5267 struct net_device *dev = info->user_ptr[1]; 5268 struct mpath_info pinfo; 5269 struct sk_buff *msg; 5270 u8 *dst = NULL; 5271 u8 next_hop[ETH_ALEN]; 5272 5273 memset(&pinfo, 0, sizeof(pinfo)); 5274 5275 if (!info->attrs[NL80211_ATTR_MAC]) 5276 return -EINVAL; 5277 5278 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5279 5280 if (!rdev->ops->get_mpath) 5281 return -EOPNOTSUPP; 5282 5283 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) 5284 return -EOPNOTSUPP; 5285 5286 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo); 5287 if (err) 5288 return err; 5289 5290 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 5291 if (!msg) 5292 return -ENOMEM; 5293 5294 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0, 5295 dev, dst, next_hop, &pinfo) < 0) { 5296 nlmsg_free(msg); 5297 return -ENOBUFS; 5298 } 5299 5300 return genlmsg_reply(msg, info); 5301 } 5302 5303 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info) 5304 { 5305 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5306 struct net_device *dev = info->user_ptr[1]; 5307 u8 *dst = NULL; 5308 u8 *next_hop = NULL; 5309 5310 if (!info->attrs[NL80211_ATTR_MAC]) 5311 return -EINVAL; 5312 5313 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]) 5314 return -EINVAL; 5315 5316 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5317 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]); 5318 5319 if (!rdev->ops->change_mpath) 5320 return -EOPNOTSUPP; 5321 5322 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) 5323 return -EOPNOTSUPP; 5324 5325 return rdev_change_mpath(rdev, dev, dst, next_hop); 5326 } 5327 5328 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info) 5329 { 5330 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5331 struct net_device *dev = info->user_ptr[1]; 5332 u8 *dst = NULL; 5333 u8 *next_hop = NULL; 5334 5335 if (!info->attrs[NL80211_ATTR_MAC]) 5336 return -EINVAL; 5337 5338 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]) 5339 return -EINVAL; 5340 5341 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5342 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]); 5343 5344 if (!rdev->ops->add_mpath) 5345 return -EOPNOTSUPP; 5346 5347 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) 5348 return -EOPNOTSUPP; 5349 5350 return rdev_add_mpath(rdev, dev, dst, next_hop); 5351 } 5352 5353 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info) 5354 { 5355 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5356 struct net_device *dev = info->user_ptr[1]; 5357 u8 *dst = NULL; 5358 5359 if (info->attrs[NL80211_ATTR_MAC]) 5360 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5361 5362 if (!rdev->ops->del_mpath) 5363 return -EOPNOTSUPP; 5364 5365 return rdev_del_mpath(rdev, dev, dst); 5366 } 5367 5368 static int nl80211_get_mpp(struct sk_buff *skb, struct genl_info *info) 5369 { 5370 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5371 int err; 5372 struct net_device *dev = info->user_ptr[1]; 5373 struct mpath_info pinfo; 5374 struct sk_buff *msg; 5375 u8 *dst = NULL; 5376 u8 mpp[ETH_ALEN]; 5377 5378 memset(&pinfo, 0, sizeof(pinfo)); 5379 5380 if (!info->attrs[NL80211_ATTR_MAC]) 5381 return -EINVAL; 5382 5383 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5384 5385 if (!rdev->ops->get_mpp) 5386 return -EOPNOTSUPP; 5387 5388 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) 5389 return -EOPNOTSUPP; 5390 5391 err = rdev_get_mpp(rdev, dev, dst, mpp, &pinfo); 5392 if (err) 5393 return err; 5394 5395 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 5396 if (!msg) 5397 return -ENOMEM; 5398 5399 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0, 5400 dev, dst, mpp, &pinfo) < 0) { 5401 nlmsg_free(msg); 5402 return -ENOBUFS; 5403 } 5404 5405 return genlmsg_reply(msg, info); 5406 } 5407 5408 static int nl80211_dump_mpp(struct sk_buff *skb, 5409 struct netlink_callback *cb) 5410 { 5411 struct mpath_info pinfo; 5412 struct cfg80211_registered_device *rdev; 5413 struct wireless_dev *wdev; 5414 u8 dst[ETH_ALEN]; 5415 u8 mpp[ETH_ALEN]; 5416 int path_idx = cb->args[2]; 5417 int err; 5418 5419 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 5420 if (err) 5421 return err; 5422 5423 if (!rdev->ops->dump_mpp) { 5424 err = -EOPNOTSUPP; 5425 goto out_err; 5426 } 5427 5428 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) { 5429 err = -EOPNOTSUPP; 5430 goto out_err; 5431 } 5432 5433 while (1) { 5434 err = rdev_dump_mpp(rdev, wdev->netdev, path_idx, dst, 5435 mpp, &pinfo); 5436 if (err == -ENOENT) 5437 break; 5438 if (err) 5439 goto out_err; 5440 5441 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid, 5442 cb->nlh->nlmsg_seq, NLM_F_MULTI, 5443 wdev->netdev, dst, mpp, 5444 &pinfo) < 0) 5445 goto out; 5446 5447 path_idx++; 5448 } 5449 5450 out: 5451 cb->args[2] = path_idx; 5452 err = skb->len; 5453 out_err: 5454 nl80211_finish_wdev_dump(rdev); 5455 return err; 5456 } 5457 5458 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info) 5459 { 5460 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5461 struct net_device *dev = info->user_ptr[1]; 5462 struct wireless_dev *wdev = dev->ieee80211_ptr; 5463 struct bss_parameters params; 5464 int err; 5465 5466 memset(¶ms, 0, sizeof(params)); 5467 /* default to not changing parameters */ 5468 params.use_cts_prot = -1; 5469 params.use_short_preamble = -1; 5470 params.use_short_slot_time = -1; 5471 params.ap_isolate = -1; 5472 params.ht_opmode = -1; 5473 params.p2p_ctwindow = -1; 5474 params.p2p_opp_ps = -1; 5475 5476 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT]) 5477 params.use_cts_prot = 5478 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]); 5479 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]) 5480 params.use_short_preamble = 5481 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]); 5482 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]) 5483 params.use_short_slot_time = 5484 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]); 5485 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) { 5486 params.basic_rates = 5487 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 5488 params.basic_rates_len = 5489 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 5490 } 5491 if (info->attrs[NL80211_ATTR_AP_ISOLATE]) 5492 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]); 5493 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE]) 5494 params.ht_opmode = 5495 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]); 5496 5497 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) { 5498 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 5499 return -EINVAL; 5500 params.p2p_ctwindow = 5501 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]); 5502 if (params.p2p_ctwindow < 0) 5503 return -EINVAL; 5504 if (params.p2p_ctwindow != 0 && 5505 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN)) 5506 return -EINVAL; 5507 } 5508 5509 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) { 5510 u8 tmp; 5511 5512 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 5513 return -EINVAL; 5514 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]); 5515 if (tmp > 1) 5516 return -EINVAL; 5517 params.p2p_opp_ps = tmp; 5518 if (params.p2p_opp_ps && 5519 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS)) 5520 return -EINVAL; 5521 } 5522 5523 if (!rdev->ops->change_bss) 5524 return -EOPNOTSUPP; 5525 5526 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 5527 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 5528 return -EOPNOTSUPP; 5529 5530 wdev_lock(wdev); 5531 err = rdev_change_bss(rdev, dev, ¶ms); 5532 wdev_unlock(wdev); 5533 5534 return err; 5535 } 5536 5537 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info) 5538 { 5539 char *data = NULL; 5540 bool is_indoor; 5541 enum nl80211_user_reg_hint_type user_reg_hint_type; 5542 u32 owner_nlportid; 5543 5544 /* 5545 * You should only get this when cfg80211 hasn't yet initialized 5546 * completely when built-in to the kernel right between the time 5547 * window between nl80211_init() and regulatory_init(), if that is 5548 * even possible. 5549 */ 5550 if (unlikely(!rcu_access_pointer(cfg80211_regdomain))) 5551 return -EINPROGRESS; 5552 5553 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]) 5554 user_reg_hint_type = 5555 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]); 5556 else 5557 user_reg_hint_type = NL80211_USER_REG_HINT_USER; 5558 5559 switch (user_reg_hint_type) { 5560 case NL80211_USER_REG_HINT_USER: 5561 case NL80211_USER_REG_HINT_CELL_BASE: 5562 if (!info->attrs[NL80211_ATTR_REG_ALPHA2]) 5563 return -EINVAL; 5564 5565 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]); 5566 return regulatory_hint_user(data, user_reg_hint_type); 5567 case NL80211_USER_REG_HINT_INDOOR: 5568 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) { 5569 owner_nlportid = info->snd_portid; 5570 is_indoor = !!info->attrs[NL80211_ATTR_REG_INDOOR]; 5571 } else { 5572 owner_nlportid = 0; 5573 is_indoor = true; 5574 } 5575 5576 return regulatory_hint_indoor(is_indoor, owner_nlportid); 5577 default: 5578 return -EINVAL; 5579 } 5580 } 5581 5582 static int nl80211_get_mesh_config(struct sk_buff *skb, 5583 struct genl_info *info) 5584 { 5585 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5586 struct net_device *dev = info->user_ptr[1]; 5587 struct wireless_dev *wdev = dev->ieee80211_ptr; 5588 struct mesh_config cur_params; 5589 int err = 0; 5590 void *hdr; 5591 struct nlattr *pinfoattr; 5592 struct sk_buff *msg; 5593 5594 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) 5595 return -EOPNOTSUPP; 5596 5597 if (!rdev->ops->get_mesh_config) 5598 return -EOPNOTSUPP; 5599 5600 wdev_lock(wdev); 5601 /* If not connected, get default parameters */ 5602 if (!wdev->mesh_id_len) 5603 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params)); 5604 else 5605 err = rdev_get_mesh_config(rdev, dev, &cur_params); 5606 wdev_unlock(wdev); 5607 5608 if (err) 5609 return err; 5610 5611 /* Draw up a netlink message to send back */ 5612 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 5613 if (!msg) 5614 return -ENOMEM; 5615 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 5616 NL80211_CMD_GET_MESH_CONFIG); 5617 if (!hdr) 5618 goto out; 5619 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG); 5620 if (!pinfoattr) 5621 goto nla_put_failure; 5622 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 5623 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT, 5624 cur_params.dot11MeshRetryTimeout) || 5625 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT, 5626 cur_params.dot11MeshConfirmTimeout) || 5627 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT, 5628 cur_params.dot11MeshHoldingTimeout) || 5629 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS, 5630 cur_params.dot11MeshMaxPeerLinks) || 5631 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES, 5632 cur_params.dot11MeshMaxRetries) || 5633 nla_put_u8(msg, NL80211_MESHCONF_TTL, 5634 cur_params.dot11MeshTTL) || 5635 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL, 5636 cur_params.element_ttl) || 5637 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS, 5638 cur_params.auto_open_plinks) || 5639 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR, 5640 cur_params.dot11MeshNbrOffsetMaxNeighbor) || 5641 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES, 5642 cur_params.dot11MeshHWMPmaxPREQretries) || 5643 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME, 5644 cur_params.path_refresh_time) || 5645 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT, 5646 cur_params.min_discovery_timeout) || 5647 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT, 5648 cur_params.dot11MeshHWMPactivePathTimeout) || 5649 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL, 5650 cur_params.dot11MeshHWMPpreqMinInterval) || 5651 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL, 5652 cur_params.dot11MeshHWMPperrMinInterval) || 5653 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME, 5654 cur_params.dot11MeshHWMPnetDiameterTraversalTime) || 5655 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE, 5656 cur_params.dot11MeshHWMPRootMode) || 5657 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL, 5658 cur_params.dot11MeshHWMPRannInterval) || 5659 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS, 5660 cur_params.dot11MeshGateAnnouncementProtocol) || 5661 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING, 5662 cur_params.dot11MeshForwarding) || 5663 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD, 5664 cur_params.rssi_threshold) || 5665 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE, 5666 cur_params.ht_opmode) || 5667 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT, 5668 cur_params.dot11MeshHWMPactivePathToRootTimeout) || 5669 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL, 5670 cur_params.dot11MeshHWMProotInterval) || 5671 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL, 5672 cur_params.dot11MeshHWMPconfirmationInterval) || 5673 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE, 5674 cur_params.power_mode) || 5675 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW, 5676 cur_params.dot11MeshAwakeWindowDuration) || 5677 nla_put_u32(msg, NL80211_MESHCONF_PLINK_TIMEOUT, 5678 cur_params.plink_timeout)) 5679 goto nla_put_failure; 5680 nla_nest_end(msg, pinfoattr); 5681 genlmsg_end(msg, hdr); 5682 return genlmsg_reply(msg, info); 5683 5684 nla_put_failure: 5685 genlmsg_cancel(msg, hdr); 5686 out: 5687 nlmsg_free(msg); 5688 return -ENOBUFS; 5689 } 5690 5691 static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = { 5692 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 }, 5693 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 }, 5694 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 }, 5695 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 }, 5696 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 }, 5697 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 }, 5698 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 }, 5699 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 }, 5700 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 }, 5701 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 }, 5702 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 }, 5703 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 }, 5704 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 }, 5705 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 }, 5706 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 }, 5707 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 }, 5708 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 }, 5709 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 }, 5710 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 }, 5711 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 }, 5712 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 }, 5713 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 }, 5714 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 }, 5715 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 }, 5716 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 }, 5717 [NL80211_MESHCONF_POWER_MODE] = { .type = NLA_U32 }, 5718 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 }, 5719 [NL80211_MESHCONF_PLINK_TIMEOUT] = { .type = NLA_U32 }, 5720 }; 5721 5722 static const struct nla_policy 5723 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = { 5724 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 }, 5725 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 }, 5726 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 }, 5727 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG }, 5728 [NL80211_MESH_SETUP_AUTH_PROTOCOL] = { .type = NLA_U8 }, 5729 [NL80211_MESH_SETUP_USERSPACE_MPM] = { .type = NLA_FLAG }, 5730 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY, 5731 .len = IEEE80211_MAX_DATA_LEN }, 5732 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG }, 5733 }; 5734 5735 static int nl80211_check_bool(const struct nlattr *nla, u8 min, u8 max, bool *out) 5736 { 5737 u8 val = nla_get_u8(nla); 5738 if (val < min || val > max) 5739 return -EINVAL; 5740 *out = val; 5741 return 0; 5742 } 5743 5744 static int nl80211_check_u8(const struct nlattr *nla, u8 min, u8 max, u8 *out) 5745 { 5746 u8 val = nla_get_u8(nla); 5747 if (val < min || val > max) 5748 return -EINVAL; 5749 *out = val; 5750 return 0; 5751 } 5752 5753 static int nl80211_check_u16(const struct nlattr *nla, u16 min, u16 max, u16 *out) 5754 { 5755 u16 val = nla_get_u16(nla); 5756 if (val < min || val > max) 5757 return -EINVAL; 5758 *out = val; 5759 return 0; 5760 } 5761 5762 static int nl80211_check_u32(const struct nlattr *nla, u32 min, u32 max, u32 *out) 5763 { 5764 u32 val = nla_get_u32(nla); 5765 if (val < min || val > max) 5766 return -EINVAL; 5767 *out = val; 5768 return 0; 5769 } 5770 5771 static int nl80211_check_s32(const struct nlattr *nla, s32 min, s32 max, s32 *out) 5772 { 5773 s32 val = nla_get_s32(nla); 5774 if (val < min || val > max) 5775 return -EINVAL; 5776 *out = val; 5777 return 0; 5778 } 5779 5780 static int nl80211_check_power_mode(const struct nlattr *nla, 5781 enum nl80211_mesh_power_mode min, 5782 enum nl80211_mesh_power_mode max, 5783 enum nl80211_mesh_power_mode *out) 5784 { 5785 u32 val = nla_get_u32(nla); 5786 if (val < min || val > max) 5787 return -EINVAL; 5788 *out = val; 5789 return 0; 5790 } 5791 5792 static int nl80211_parse_mesh_config(struct genl_info *info, 5793 struct mesh_config *cfg, 5794 u32 *mask_out) 5795 { 5796 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1]; 5797 u32 mask = 0; 5798 u16 ht_opmode; 5799 5800 #define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, min, max, mask, attr, fn) \ 5801 do { \ 5802 if (tb[attr]) { \ 5803 if (fn(tb[attr], min, max, &cfg->param)) \ 5804 return -EINVAL; \ 5805 mask |= (1 << (attr - 1)); \ 5806 } \ 5807 } while (0) 5808 5809 if (!info->attrs[NL80211_ATTR_MESH_CONFIG]) 5810 return -EINVAL; 5811 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX, 5812 info->attrs[NL80211_ATTR_MESH_CONFIG], 5813 nl80211_meshconf_params_policy)) 5814 return -EINVAL; 5815 5816 /* This makes sure that there aren't more than 32 mesh config 5817 * parameters (otherwise our bitfield scheme would not work.) */ 5818 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32); 5819 5820 /* Fill in the params struct */ 5821 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, 1, 255, 5822 mask, NL80211_MESHCONF_RETRY_TIMEOUT, 5823 nl80211_check_u16); 5824 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, 1, 255, 5825 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, 5826 nl80211_check_u16); 5827 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, 1, 255, 5828 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, 5829 nl80211_check_u16); 5830 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, 0, 255, 5831 mask, NL80211_MESHCONF_MAX_PEER_LINKS, 5832 nl80211_check_u16); 5833 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, 0, 16, 5834 mask, NL80211_MESHCONF_MAX_RETRIES, 5835 nl80211_check_u8); 5836 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, 1, 255, 5837 mask, NL80211_MESHCONF_TTL, nl80211_check_u8); 5838 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, 1, 255, 5839 mask, NL80211_MESHCONF_ELEMENT_TTL, 5840 nl80211_check_u8); 5841 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, 0, 1, 5842 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, 5843 nl80211_check_bool); 5844 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor, 5845 1, 255, mask, 5846 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR, 5847 nl80211_check_u32); 5848 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, 0, 255, 5849 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES, 5850 nl80211_check_u8); 5851 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, 1, 65535, 5852 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, 5853 nl80211_check_u32); 5854 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, 1, 65535, 5855 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT, 5856 nl80211_check_u16); 5857 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout, 5858 1, 65535, mask, 5859 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT, 5860 nl80211_check_u32); 5861 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval, 5862 1, 65535, mask, 5863 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL, 5864 nl80211_check_u16); 5865 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval, 5866 1, 65535, mask, 5867 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL, 5868 nl80211_check_u16); 5869 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, 5870 dot11MeshHWMPnetDiameterTraversalTime, 5871 1, 65535, mask, 5872 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME, 5873 nl80211_check_u16); 5874 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, 0, 4, 5875 mask, NL80211_MESHCONF_HWMP_ROOTMODE, 5876 nl80211_check_u8); 5877 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, 1, 65535, 5878 mask, NL80211_MESHCONF_HWMP_RANN_INTERVAL, 5879 nl80211_check_u16); 5880 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, 5881 dot11MeshGateAnnouncementProtocol, 0, 1, 5882 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS, 5883 nl80211_check_bool); 5884 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, 0, 1, 5885 mask, NL80211_MESHCONF_FORWARDING, 5886 nl80211_check_bool); 5887 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, -255, 0, 5888 mask, NL80211_MESHCONF_RSSI_THRESHOLD, 5889 nl80211_check_s32); 5890 /* 5891 * Check HT operation mode based on 5892 * IEEE 802.11 2012 8.4.2.59 HT Operation element. 5893 */ 5894 if (tb[NL80211_MESHCONF_HT_OPMODE]) { 5895 ht_opmode = nla_get_u16(tb[NL80211_MESHCONF_HT_OPMODE]); 5896 5897 if (ht_opmode & ~(IEEE80211_HT_OP_MODE_PROTECTION | 5898 IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT | 5899 IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT)) 5900 return -EINVAL; 5901 5902 if ((ht_opmode & IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT) && 5903 (ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT)) 5904 return -EINVAL; 5905 5906 switch (ht_opmode & IEEE80211_HT_OP_MODE_PROTECTION) { 5907 case IEEE80211_HT_OP_MODE_PROTECTION_NONE: 5908 case IEEE80211_HT_OP_MODE_PROTECTION_20MHZ: 5909 if (ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT) 5910 return -EINVAL; 5911 break; 5912 case IEEE80211_HT_OP_MODE_PROTECTION_NONMEMBER: 5913 case IEEE80211_HT_OP_MODE_PROTECTION_NONHT_MIXED: 5914 if (!(ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT)) 5915 return -EINVAL; 5916 break; 5917 } 5918 cfg->ht_opmode = ht_opmode; 5919 } 5920 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout, 5921 1, 65535, mask, 5922 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT, 5923 nl80211_check_u32); 5924 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, 1, 65535, 5925 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL, 5926 nl80211_check_u16); 5927 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, 5928 dot11MeshHWMPconfirmationInterval, 5929 1, 65535, mask, 5930 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL, 5931 nl80211_check_u16); 5932 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode, 5933 NL80211_MESH_POWER_ACTIVE, 5934 NL80211_MESH_POWER_MAX, 5935 mask, NL80211_MESHCONF_POWER_MODE, 5936 nl80211_check_power_mode); 5937 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration, 5938 0, 65535, mask, 5939 NL80211_MESHCONF_AWAKE_WINDOW, nl80211_check_u16); 5940 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, plink_timeout, 0, 0xffffffff, 5941 mask, NL80211_MESHCONF_PLINK_TIMEOUT, 5942 nl80211_check_u32); 5943 if (mask_out) 5944 *mask_out = mask; 5945 5946 return 0; 5947 5948 #undef FILL_IN_MESH_PARAM_IF_SET 5949 } 5950 5951 static int nl80211_parse_mesh_setup(struct genl_info *info, 5952 struct mesh_setup *setup) 5953 { 5954 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5955 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1]; 5956 5957 if (!info->attrs[NL80211_ATTR_MESH_SETUP]) 5958 return -EINVAL; 5959 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX, 5960 info->attrs[NL80211_ATTR_MESH_SETUP], 5961 nl80211_mesh_setup_params_policy)) 5962 return -EINVAL; 5963 5964 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC]) 5965 setup->sync_method = 5966 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ? 5967 IEEE80211_SYNC_METHOD_VENDOR : 5968 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET; 5969 5970 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL]) 5971 setup->path_sel_proto = 5972 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ? 5973 IEEE80211_PATH_PROTOCOL_VENDOR : 5974 IEEE80211_PATH_PROTOCOL_HWMP; 5975 5976 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC]) 5977 setup->path_metric = 5978 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ? 5979 IEEE80211_PATH_METRIC_VENDOR : 5980 IEEE80211_PATH_METRIC_AIRTIME; 5981 5982 if (tb[NL80211_MESH_SETUP_IE]) { 5983 struct nlattr *ieattr = 5984 tb[NL80211_MESH_SETUP_IE]; 5985 if (!is_valid_ie_attr(ieattr)) 5986 return -EINVAL; 5987 setup->ie = nla_data(ieattr); 5988 setup->ie_len = nla_len(ieattr); 5989 } 5990 if (tb[NL80211_MESH_SETUP_USERSPACE_MPM] && 5991 !(rdev->wiphy.features & NL80211_FEATURE_USERSPACE_MPM)) 5992 return -EINVAL; 5993 setup->user_mpm = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_MPM]); 5994 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]); 5995 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]); 5996 if (setup->is_secure) 5997 setup->user_mpm = true; 5998 5999 if (tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]) { 6000 if (!setup->user_mpm) 6001 return -EINVAL; 6002 setup->auth_id = 6003 nla_get_u8(tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]); 6004 } 6005 6006 return 0; 6007 } 6008 6009 static int nl80211_update_mesh_config(struct sk_buff *skb, 6010 struct genl_info *info) 6011 { 6012 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 6013 struct net_device *dev = info->user_ptr[1]; 6014 struct wireless_dev *wdev = dev->ieee80211_ptr; 6015 struct mesh_config cfg; 6016 u32 mask; 6017 int err; 6018 6019 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) 6020 return -EOPNOTSUPP; 6021 6022 if (!rdev->ops->update_mesh_config) 6023 return -EOPNOTSUPP; 6024 6025 err = nl80211_parse_mesh_config(info, &cfg, &mask); 6026 if (err) 6027 return err; 6028 6029 wdev_lock(wdev); 6030 if (!wdev->mesh_id_len) 6031 err = -ENOLINK; 6032 6033 if (!err) 6034 err = rdev_update_mesh_config(rdev, dev, mask, &cfg); 6035 6036 wdev_unlock(wdev); 6037 6038 return err; 6039 } 6040 6041 static int nl80211_put_regdom(const struct ieee80211_regdomain *regdom, 6042 struct sk_buff *msg) 6043 { 6044 struct nlattr *nl_reg_rules; 6045 unsigned int i; 6046 6047 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) || 6048 (regdom->dfs_region && 6049 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region))) 6050 goto nla_put_failure; 6051 6052 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES); 6053 if (!nl_reg_rules) 6054 goto nla_put_failure; 6055 6056 for (i = 0; i < regdom->n_reg_rules; i++) { 6057 struct nlattr *nl_reg_rule; 6058 const struct ieee80211_reg_rule *reg_rule; 6059 const struct ieee80211_freq_range *freq_range; 6060 const struct ieee80211_power_rule *power_rule; 6061 unsigned int max_bandwidth_khz; 6062 6063 reg_rule = ®dom->reg_rules[i]; 6064 freq_range = ®_rule->freq_range; 6065 power_rule = ®_rule->power_rule; 6066 6067 nl_reg_rule = nla_nest_start(msg, i); 6068 if (!nl_reg_rule) 6069 goto nla_put_failure; 6070 6071 max_bandwidth_khz = freq_range->max_bandwidth_khz; 6072 if (!max_bandwidth_khz) 6073 max_bandwidth_khz = reg_get_max_bandwidth(regdom, 6074 reg_rule); 6075 6076 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS, 6077 reg_rule->flags) || 6078 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START, 6079 freq_range->start_freq_khz) || 6080 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END, 6081 freq_range->end_freq_khz) || 6082 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW, 6083 max_bandwidth_khz) || 6084 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN, 6085 power_rule->max_antenna_gain) || 6086 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP, 6087 power_rule->max_eirp) || 6088 nla_put_u32(msg, NL80211_ATTR_DFS_CAC_TIME, 6089 reg_rule->dfs_cac_ms)) 6090 goto nla_put_failure; 6091 6092 nla_nest_end(msg, nl_reg_rule); 6093 } 6094 6095 nla_nest_end(msg, nl_reg_rules); 6096 return 0; 6097 6098 nla_put_failure: 6099 return -EMSGSIZE; 6100 } 6101 6102 static int nl80211_get_reg_do(struct sk_buff *skb, struct genl_info *info) 6103 { 6104 const struct ieee80211_regdomain *regdom = NULL; 6105 struct cfg80211_registered_device *rdev; 6106 struct wiphy *wiphy = NULL; 6107 struct sk_buff *msg; 6108 void *hdr; 6109 6110 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 6111 if (!msg) 6112 return -ENOBUFS; 6113 6114 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 6115 NL80211_CMD_GET_REG); 6116 if (!hdr) 6117 goto put_failure; 6118 6119 if (info->attrs[NL80211_ATTR_WIPHY]) { 6120 bool self_managed; 6121 6122 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info); 6123 if (IS_ERR(rdev)) { 6124 nlmsg_free(msg); 6125 return PTR_ERR(rdev); 6126 } 6127 6128 wiphy = &rdev->wiphy; 6129 self_managed = wiphy->regulatory_flags & 6130 REGULATORY_WIPHY_SELF_MANAGED; 6131 regdom = get_wiphy_regdom(wiphy); 6132 6133 /* a self-managed-reg device must have a private regdom */ 6134 if (WARN_ON(!regdom && self_managed)) { 6135 nlmsg_free(msg); 6136 return -EINVAL; 6137 } 6138 6139 if (regdom && 6140 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy))) 6141 goto nla_put_failure; 6142 } 6143 6144 if (!wiphy && reg_last_request_cell_base() && 6145 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE, 6146 NL80211_USER_REG_HINT_CELL_BASE)) 6147 goto nla_put_failure; 6148 6149 rcu_read_lock(); 6150 6151 if (!regdom) 6152 regdom = rcu_dereference(cfg80211_regdomain); 6153 6154 if (nl80211_put_regdom(regdom, msg)) 6155 goto nla_put_failure_rcu; 6156 6157 rcu_read_unlock(); 6158 6159 genlmsg_end(msg, hdr); 6160 return genlmsg_reply(msg, info); 6161 6162 nla_put_failure_rcu: 6163 rcu_read_unlock(); 6164 nla_put_failure: 6165 genlmsg_cancel(msg, hdr); 6166 put_failure: 6167 nlmsg_free(msg); 6168 return -EMSGSIZE; 6169 } 6170 6171 static int nl80211_send_regdom(struct sk_buff *msg, struct netlink_callback *cb, 6172 u32 seq, int flags, struct wiphy *wiphy, 6173 const struct ieee80211_regdomain *regdom) 6174 { 6175 void *hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags, 6176 NL80211_CMD_GET_REG); 6177 6178 if (!hdr) 6179 return -1; 6180 6181 genl_dump_check_consistent(cb, hdr, &nl80211_fam); 6182 6183 if (nl80211_put_regdom(regdom, msg)) 6184 goto nla_put_failure; 6185 6186 if (!wiphy && reg_last_request_cell_base() && 6187 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE, 6188 NL80211_USER_REG_HINT_CELL_BASE)) 6189 goto nla_put_failure; 6190 6191 if (wiphy && 6192 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy))) 6193 goto nla_put_failure; 6194 6195 if (wiphy && wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED && 6196 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG)) 6197 goto nla_put_failure; 6198 6199 genlmsg_end(msg, hdr); 6200 return 0; 6201 6202 nla_put_failure: 6203 genlmsg_cancel(msg, hdr); 6204 return -EMSGSIZE; 6205 } 6206 6207 static int nl80211_get_reg_dump(struct sk_buff *skb, 6208 struct netlink_callback *cb) 6209 { 6210 const struct ieee80211_regdomain *regdom = NULL; 6211 struct cfg80211_registered_device *rdev; 6212 int err, reg_idx, start = cb->args[2]; 6213 6214 rtnl_lock(); 6215 6216 if (cfg80211_regdomain && start == 0) { 6217 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq, 6218 NLM_F_MULTI, NULL, 6219 rtnl_dereference(cfg80211_regdomain)); 6220 if (err < 0) 6221 goto out_err; 6222 } 6223 6224 /* the global regdom is idx 0 */ 6225 reg_idx = 1; 6226 list_for_each_entry(rdev, &cfg80211_rdev_list, list) { 6227 regdom = get_wiphy_regdom(&rdev->wiphy); 6228 if (!regdom) 6229 continue; 6230 6231 if (++reg_idx <= start) 6232 continue; 6233 6234 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq, 6235 NLM_F_MULTI, &rdev->wiphy, regdom); 6236 if (err < 0) { 6237 reg_idx--; 6238 break; 6239 } 6240 } 6241 6242 cb->args[2] = reg_idx; 6243 err = skb->len; 6244 out_err: 6245 rtnl_unlock(); 6246 return err; 6247 } 6248 6249 #ifdef CONFIG_CFG80211_CRDA_SUPPORT 6250 static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = { 6251 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 }, 6252 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 }, 6253 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 }, 6254 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 }, 6255 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 }, 6256 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 }, 6257 [NL80211_ATTR_DFS_CAC_TIME] = { .type = NLA_U32 }, 6258 }; 6259 6260 static int parse_reg_rule(struct nlattr *tb[], 6261 struct ieee80211_reg_rule *reg_rule) 6262 { 6263 struct ieee80211_freq_range *freq_range = ®_rule->freq_range; 6264 struct ieee80211_power_rule *power_rule = ®_rule->power_rule; 6265 6266 if (!tb[NL80211_ATTR_REG_RULE_FLAGS]) 6267 return -EINVAL; 6268 if (!tb[NL80211_ATTR_FREQ_RANGE_START]) 6269 return -EINVAL; 6270 if (!tb[NL80211_ATTR_FREQ_RANGE_END]) 6271 return -EINVAL; 6272 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]) 6273 return -EINVAL; 6274 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]) 6275 return -EINVAL; 6276 6277 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]); 6278 6279 freq_range->start_freq_khz = 6280 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]); 6281 freq_range->end_freq_khz = 6282 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]); 6283 freq_range->max_bandwidth_khz = 6284 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]); 6285 6286 power_rule->max_eirp = 6287 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]); 6288 6289 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]) 6290 power_rule->max_antenna_gain = 6291 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]); 6292 6293 if (tb[NL80211_ATTR_DFS_CAC_TIME]) 6294 reg_rule->dfs_cac_ms = 6295 nla_get_u32(tb[NL80211_ATTR_DFS_CAC_TIME]); 6296 6297 return 0; 6298 } 6299 6300 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info) 6301 { 6302 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1]; 6303 struct nlattr *nl_reg_rule; 6304 char *alpha2; 6305 int rem_reg_rules, r; 6306 u32 num_rules = 0, rule_idx = 0, size_of_regd; 6307 enum nl80211_dfs_regions dfs_region = NL80211_DFS_UNSET; 6308 struct ieee80211_regdomain *rd; 6309 6310 if (!info->attrs[NL80211_ATTR_REG_ALPHA2]) 6311 return -EINVAL; 6312 6313 if (!info->attrs[NL80211_ATTR_REG_RULES]) 6314 return -EINVAL; 6315 6316 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]); 6317 6318 if (info->attrs[NL80211_ATTR_DFS_REGION]) 6319 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]); 6320 6321 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES], 6322 rem_reg_rules) { 6323 num_rules++; 6324 if (num_rules > NL80211_MAX_SUPP_REG_RULES) 6325 return -EINVAL; 6326 } 6327 6328 if (!reg_is_valid_request(alpha2)) 6329 return -EINVAL; 6330 6331 size_of_regd = sizeof(struct ieee80211_regdomain) + 6332 num_rules * sizeof(struct ieee80211_reg_rule); 6333 6334 rd = kzalloc(size_of_regd, GFP_KERNEL); 6335 if (!rd) 6336 return -ENOMEM; 6337 6338 rd->n_reg_rules = num_rules; 6339 rd->alpha2[0] = alpha2[0]; 6340 rd->alpha2[1] = alpha2[1]; 6341 6342 /* 6343 * Disable DFS master mode if the DFS region was 6344 * not supported or known on this kernel. 6345 */ 6346 if (reg_supported_dfs_region(dfs_region)) 6347 rd->dfs_region = dfs_region; 6348 6349 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES], 6350 rem_reg_rules) { 6351 r = nla_parse_nested(tb, NL80211_REG_RULE_ATTR_MAX, 6352 nl_reg_rule, reg_rule_policy); 6353 if (r) 6354 goto bad_reg; 6355 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]); 6356 if (r) 6357 goto bad_reg; 6358 6359 rule_idx++; 6360 6361 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) { 6362 r = -EINVAL; 6363 goto bad_reg; 6364 } 6365 } 6366 6367 /* set_regdom takes ownership of rd */ 6368 return set_regdom(rd, REGD_SOURCE_CRDA); 6369 bad_reg: 6370 kfree(rd); 6371 return r; 6372 } 6373 #endif /* CONFIG_CFG80211_CRDA_SUPPORT */ 6374 6375 static int validate_scan_freqs(struct nlattr *freqs) 6376 { 6377 struct nlattr *attr1, *attr2; 6378 int n_channels = 0, tmp1, tmp2; 6379 6380 nla_for_each_nested(attr1, freqs, tmp1) { 6381 n_channels++; 6382 /* 6383 * Some hardware has a limited channel list for 6384 * scanning, and it is pretty much nonsensical 6385 * to scan for a channel twice, so disallow that 6386 * and don't require drivers to check that the 6387 * channel list they get isn't longer than what 6388 * they can scan, as long as they can scan all 6389 * the channels they registered at once. 6390 */ 6391 nla_for_each_nested(attr2, freqs, tmp2) 6392 if (attr1 != attr2 && 6393 nla_get_u32(attr1) == nla_get_u32(attr2)) 6394 return 0; 6395 } 6396 6397 return n_channels; 6398 } 6399 6400 static bool is_band_valid(struct wiphy *wiphy, enum nl80211_band b) 6401 { 6402 return b < NUM_NL80211_BANDS && wiphy->bands[b]; 6403 } 6404 6405 static int parse_bss_select(struct nlattr *nla, struct wiphy *wiphy, 6406 struct cfg80211_bss_selection *bss_select) 6407 { 6408 struct nlattr *attr[NL80211_BSS_SELECT_ATTR_MAX + 1]; 6409 struct nlattr *nest; 6410 int err; 6411 bool found = false; 6412 int i; 6413 6414 /* only process one nested attribute */ 6415 nest = nla_data(nla); 6416 if (!nla_ok(nest, nla_len(nest))) 6417 return -EINVAL; 6418 6419 err = nla_parse_nested(attr, NL80211_BSS_SELECT_ATTR_MAX, nest, 6420 nl80211_bss_select_policy); 6421 if (err) 6422 return err; 6423 6424 /* only one attribute may be given */ 6425 for (i = 0; i <= NL80211_BSS_SELECT_ATTR_MAX; i++) { 6426 if (attr[i]) { 6427 if (found) 6428 return -EINVAL; 6429 found = true; 6430 } 6431 } 6432 6433 bss_select->behaviour = __NL80211_BSS_SELECT_ATTR_INVALID; 6434 6435 if (attr[NL80211_BSS_SELECT_ATTR_RSSI]) 6436 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI; 6437 6438 if (attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]) { 6439 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_BAND_PREF; 6440 bss_select->param.band_pref = 6441 nla_get_u32(attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]); 6442 if (!is_band_valid(wiphy, bss_select->param.band_pref)) 6443 return -EINVAL; 6444 } 6445 6446 if (attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]) { 6447 struct nl80211_bss_select_rssi_adjust *adj_param; 6448 6449 adj_param = nla_data(attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]); 6450 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI_ADJUST; 6451 bss_select->param.adjust.band = adj_param->band; 6452 bss_select->param.adjust.delta = adj_param->delta; 6453 if (!is_band_valid(wiphy, bss_select->param.adjust.band)) 6454 return -EINVAL; 6455 } 6456 6457 /* user-space did not provide behaviour attribute */ 6458 if (bss_select->behaviour == __NL80211_BSS_SELECT_ATTR_INVALID) 6459 return -EINVAL; 6460 6461 if (!(wiphy->bss_select_support & BIT(bss_select->behaviour))) 6462 return -EINVAL; 6463 6464 return 0; 6465 } 6466 6467 static int nl80211_parse_random_mac(struct nlattr **attrs, 6468 u8 *mac_addr, u8 *mac_addr_mask) 6469 { 6470 int i; 6471 6472 if (!attrs[NL80211_ATTR_MAC] && !attrs[NL80211_ATTR_MAC_MASK]) { 6473 eth_zero_addr(mac_addr); 6474 eth_zero_addr(mac_addr_mask); 6475 mac_addr[0] = 0x2; 6476 mac_addr_mask[0] = 0x3; 6477 6478 return 0; 6479 } 6480 6481 /* need both or none */ 6482 if (!attrs[NL80211_ATTR_MAC] || !attrs[NL80211_ATTR_MAC_MASK]) 6483 return -EINVAL; 6484 6485 memcpy(mac_addr, nla_data(attrs[NL80211_ATTR_MAC]), ETH_ALEN); 6486 memcpy(mac_addr_mask, nla_data(attrs[NL80211_ATTR_MAC_MASK]), ETH_ALEN); 6487 6488 /* don't allow or configure an mcast address */ 6489 if (!is_multicast_ether_addr(mac_addr_mask) || 6490 is_multicast_ether_addr(mac_addr)) 6491 return -EINVAL; 6492 6493 /* 6494 * allow users to pass a MAC address that has bits set outside 6495 * of the mask, but don't bother drivers with having to deal 6496 * with such bits 6497 */ 6498 for (i = 0; i < ETH_ALEN; i++) 6499 mac_addr[i] &= mac_addr_mask[i]; 6500 6501 return 0; 6502 } 6503 6504 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info) 6505 { 6506 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 6507 struct wireless_dev *wdev = info->user_ptr[1]; 6508 struct cfg80211_scan_request *request; 6509 struct nlattr *attr; 6510 struct wiphy *wiphy; 6511 int err, tmp, n_ssids = 0, n_channels, i; 6512 size_t ie_len; 6513 6514 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 6515 return -EINVAL; 6516 6517 wiphy = &rdev->wiphy; 6518 6519 if (wdev->iftype == NL80211_IFTYPE_NAN) 6520 return -EOPNOTSUPP; 6521 6522 if (!rdev->ops->scan) 6523 return -EOPNOTSUPP; 6524 6525 if (rdev->scan_req || rdev->scan_msg) { 6526 err = -EBUSY; 6527 goto unlock; 6528 } 6529 6530 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) { 6531 n_channels = validate_scan_freqs( 6532 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]); 6533 if (!n_channels) { 6534 err = -EINVAL; 6535 goto unlock; 6536 } 6537 } else { 6538 n_channels = ieee80211_get_num_supported_channels(wiphy); 6539 } 6540 6541 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) 6542 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) 6543 n_ssids++; 6544 6545 if (n_ssids > wiphy->max_scan_ssids) { 6546 err = -EINVAL; 6547 goto unlock; 6548 } 6549 6550 if (info->attrs[NL80211_ATTR_IE]) 6551 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 6552 else 6553 ie_len = 0; 6554 6555 if (ie_len > wiphy->max_scan_ie_len) { 6556 err = -EINVAL; 6557 goto unlock; 6558 } 6559 6560 request = kzalloc(sizeof(*request) 6561 + sizeof(*request->ssids) * n_ssids 6562 + sizeof(*request->channels) * n_channels 6563 + ie_len, GFP_KERNEL); 6564 if (!request) { 6565 err = -ENOMEM; 6566 goto unlock; 6567 } 6568 6569 if (n_ssids) 6570 request->ssids = (void *)&request->channels[n_channels]; 6571 request->n_ssids = n_ssids; 6572 if (ie_len) { 6573 if (n_ssids) 6574 request->ie = (void *)(request->ssids + n_ssids); 6575 else 6576 request->ie = (void *)(request->channels + n_channels); 6577 } 6578 6579 i = 0; 6580 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) { 6581 /* user specified, bail out if channel not found */ 6582 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) { 6583 struct ieee80211_channel *chan; 6584 6585 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr)); 6586 6587 if (!chan) { 6588 err = -EINVAL; 6589 goto out_free; 6590 } 6591 6592 /* ignore disabled channels */ 6593 if (chan->flags & IEEE80211_CHAN_DISABLED) 6594 continue; 6595 6596 request->channels[i] = chan; 6597 i++; 6598 } 6599 } else { 6600 enum nl80211_band band; 6601 6602 /* all channels */ 6603 for (band = 0; band < NUM_NL80211_BANDS; band++) { 6604 int j; 6605 6606 if (!wiphy->bands[band]) 6607 continue; 6608 for (j = 0; j < wiphy->bands[band]->n_channels; j++) { 6609 struct ieee80211_channel *chan; 6610 6611 chan = &wiphy->bands[band]->channels[j]; 6612 6613 if (chan->flags & IEEE80211_CHAN_DISABLED) 6614 continue; 6615 6616 request->channels[i] = chan; 6617 i++; 6618 } 6619 } 6620 } 6621 6622 if (!i) { 6623 err = -EINVAL; 6624 goto out_free; 6625 } 6626 6627 request->n_channels = i; 6628 6629 i = 0; 6630 if (n_ssids) { 6631 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) { 6632 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) { 6633 err = -EINVAL; 6634 goto out_free; 6635 } 6636 request->ssids[i].ssid_len = nla_len(attr); 6637 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr)); 6638 i++; 6639 } 6640 } 6641 6642 if (info->attrs[NL80211_ATTR_IE]) { 6643 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 6644 memcpy((void *)request->ie, 6645 nla_data(info->attrs[NL80211_ATTR_IE]), 6646 request->ie_len); 6647 } 6648 6649 for (i = 0; i < NUM_NL80211_BANDS; i++) 6650 if (wiphy->bands[i]) 6651 request->rates[i] = 6652 (1 << wiphy->bands[i]->n_bitrates) - 1; 6653 6654 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) { 6655 nla_for_each_nested(attr, 6656 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES], 6657 tmp) { 6658 enum nl80211_band band = nla_type(attr); 6659 6660 if (band < 0 || band >= NUM_NL80211_BANDS) { 6661 err = -EINVAL; 6662 goto out_free; 6663 } 6664 6665 if (!wiphy->bands[band]) 6666 continue; 6667 6668 err = ieee80211_get_ratemask(wiphy->bands[band], 6669 nla_data(attr), 6670 nla_len(attr), 6671 &request->rates[band]); 6672 if (err) 6673 goto out_free; 6674 } 6675 } 6676 6677 if (info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]) { 6678 if (!wiphy_ext_feature_isset(wiphy, 6679 NL80211_EXT_FEATURE_SET_SCAN_DWELL)) { 6680 err = -EOPNOTSUPP; 6681 goto out_free; 6682 } 6683 6684 request->duration = 6685 nla_get_u16(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]); 6686 request->duration_mandatory = 6687 nla_get_flag(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION_MANDATORY]); 6688 } 6689 6690 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) { 6691 request->flags = nla_get_u32( 6692 info->attrs[NL80211_ATTR_SCAN_FLAGS]); 6693 if ((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) && 6694 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) { 6695 err = -EOPNOTSUPP; 6696 goto out_free; 6697 } 6698 6699 if (request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) { 6700 if (!(wiphy->features & 6701 NL80211_FEATURE_SCAN_RANDOM_MAC_ADDR)) { 6702 err = -EOPNOTSUPP; 6703 goto out_free; 6704 } 6705 6706 if (wdev->current_bss) { 6707 err = -EOPNOTSUPP; 6708 goto out_free; 6709 } 6710 6711 err = nl80211_parse_random_mac(info->attrs, 6712 request->mac_addr, 6713 request->mac_addr_mask); 6714 if (err) 6715 goto out_free; 6716 } 6717 } 6718 6719 request->no_cck = 6720 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]); 6721 6722 /* Initial implementation used NL80211_ATTR_MAC to set the specific 6723 * BSSID to scan for. This was problematic because that same attribute 6724 * was already used for another purpose (local random MAC address). The 6725 * NL80211_ATTR_BSSID attribute was added to fix this. For backwards 6726 * compatibility with older userspace components, also use the 6727 * NL80211_ATTR_MAC value here if it can be determined to be used for 6728 * the specific BSSID use case instead of the random MAC address 6729 * (NL80211_ATTR_SCAN_FLAGS is used to enable random MAC address use). 6730 */ 6731 if (info->attrs[NL80211_ATTR_BSSID]) 6732 memcpy(request->bssid, 6733 nla_data(info->attrs[NL80211_ATTR_BSSID]), ETH_ALEN); 6734 else if (!(request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) && 6735 info->attrs[NL80211_ATTR_MAC]) 6736 memcpy(request->bssid, nla_data(info->attrs[NL80211_ATTR_MAC]), 6737 ETH_ALEN); 6738 else 6739 eth_broadcast_addr(request->bssid); 6740 6741 request->wdev = wdev; 6742 request->wiphy = &rdev->wiphy; 6743 request->scan_start = jiffies; 6744 6745 rdev->scan_req = request; 6746 err = rdev_scan(rdev, request); 6747 6748 if (!err) { 6749 nl80211_send_scan_start(rdev, wdev); 6750 if (wdev->netdev) 6751 dev_hold(wdev->netdev); 6752 } else { 6753 out_free: 6754 rdev->scan_req = NULL; 6755 kfree(request); 6756 } 6757 6758 unlock: 6759 return err; 6760 } 6761 6762 static int nl80211_abort_scan(struct sk_buff *skb, struct genl_info *info) 6763 { 6764 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 6765 struct wireless_dev *wdev = info->user_ptr[1]; 6766 6767 if (!rdev->ops->abort_scan) 6768 return -EOPNOTSUPP; 6769 6770 if (rdev->scan_msg) 6771 return 0; 6772 6773 if (!rdev->scan_req) 6774 return -ENOENT; 6775 6776 rdev_abort_scan(rdev, wdev); 6777 return 0; 6778 } 6779 6780 static int 6781 nl80211_parse_sched_scan_plans(struct wiphy *wiphy, int n_plans, 6782 struct cfg80211_sched_scan_request *request, 6783 struct nlattr **attrs) 6784 { 6785 int tmp, err, i = 0; 6786 struct nlattr *attr; 6787 6788 if (!attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) { 6789 u32 interval; 6790 6791 /* 6792 * If scan plans are not specified, 6793 * %NL80211_ATTR_SCHED_SCAN_INTERVAL must be specified. In this 6794 * case one scan plan will be set with the specified scan 6795 * interval and infinite number of iterations. 6796 */ 6797 if (!attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]) 6798 return -EINVAL; 6799 6800 interval = nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]); 6801 if (!interval) 6802 return -EINVAL; 6803 6804 request->scan_plans[0].interval = 6805 DIV_ROUND_UP(interval, MSEC_PER_SEC); 6806 if (!request->scan_plans[0].interval) 6807 return -EINVAL; 6808 6809 if (request->scan_plans[0].interval > 6810 wiphy->max_sched_scan_plan_interval) 6811 request->scan_plans[0].interval = 6812 wiphy->max_sched_scan_plan_interval; 6813 6814 return 0; 6815 } 6816 6817 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp) { 6818 struct nlattr *plan[NL80211_SCHED_SCAN_PLAN_MAX + 1]; 6819 6820 if (WARN_ON(i >= n_plans)) 6821 return -EINVAL; 6822 6823 err = nla_parse_nested(plan, NL80211_SCHED_SCAN_PLAN_MAX, 6824 attr, nl80211_plan_policy); 6825 if (err) 6826 return err; 6827 6828 if (!plan[NL80211_SCHED_SCAN_PLAN_INTERVAL]) 6829 return -EINVAL; 6830 6831 request->scan_plans[i].interval = 6832 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_INTERVAL]); 6833 if (!request->scan_plans[i].interval || 6834 request->scan_plans[i].interval > 6835 wiphy->max_sched_scan_plan_interval) 6836 return -EINVAL; 6837 6838 if (plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]) { 6839 request->scan_plans[i].iterations = 6840 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]); 6841 if (!request->scan_plans[i].iterations || 6842 (request->scan_plans[i].iterations > 6843 wiphy->max_sched_scan_plan_iterations)) 6844 return -EINVAL; 6845 } else if (i < n_plans - 1) { 6846 /* 6847 * All scan plans but the last one must specify 6848 * a finite number of iterations 6849 */ 6850 return -EINVAL; 6851 } 6852 6853 i++; 6854 } 6855 6856 /* 6857 * The last scan plan must not specify the number of 6858 * iterations, it is supposed to run infinitely 6859 */ 6860 if (request->scan_plans[n_plans - 1].iterations) 6861 return -EINVAL; 6862 6863 return 0; 6864 } 6865 6866 static struct cfg80211_sched_scan_request * 6867 nl80211_parse_sched_scan(struct wiphy *wiphy, struct wireless_dev *wdev, 6868 struct nlattr **attrs) 6869 { 6870 struct cfg80211_sched_scan_request *request; 6871 struct nlattr *attr; 6872 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i, n_plans = 0; 6873 enum nl80211_band band; 6874 size_t ie_len; 6875 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1]; 6876 s32 default_match_rssi = NL80211_SCAN_RSSI_THOLD_OFF; 6877 6878 if (!is_valid_ie_attr(attrs[NL80211_ATTR_IE])) 6879 return ERR_PTR(-EINVAL); 6880 6881 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) { 6882 n_channels = validate_scan_freqs( 6883 attrs[NL80211_ATTR_SCAN_FREQUENCIES]); 6884 if (!n_channels) 6885 return ERR_PTR(-EINVAL); 6886 } else { 6887 n_channels = ieee80211_get_num_supported_channels(wiphy); 6888 } 6889 6890 if (attrs[NL80211_ATTR_SCAN_SSIDS]) 6891 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS], 6892 tmp) 6893 n_ssids++; 6894 6895 if (n_ssids > wiphy->max_sched_scan_ssids) 6896 return ERR_PTR(-EINVAL); 6897 6898 /* 6899 * First, count the number of 'real' matchsets. Due to an issue with 6900 * the old implementation, matchsets containing only the RSSI attribute 6901 * (NL80211_SCHED_SCAN_MATCH_ATTR_RSSI) are considered as the 'default' 6902 * RSSI for all matchsets, rather than their own matchset for reporting 6903 * all APs with a strong RSSI. This is needed to be compatible with 6904 * older userspace that treated a matchset with only the RSSI as the 6905 * global RSSI for all other matchsets - if there are other matchsets. 6906 */ 6907 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) { 6908 nla_for_each_nested(attr, 6909 attrs[NL80211_ATTR_SCHED_SCAN_MATCH], 6910 tmp) { 6911 struct nlattr *rssi; 6912 6913 err = nla_parse_nested(tb, 6914 NL80211_SCHED_SCAN_MATCH_ATTR_MAX, 6915 attr, nl80211_match_policy); 6916 if (err) 6917 return ERR_PTR(err); 6918 /* add other standalone attributes here */ 6919 if (tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID]) { 6920 n_match_sets++; 6921 continue; 6922 } 6923 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI]; 6924 if (rssi) 6925 default_match_rssi = nla_get_s32(rssi); 6926 } 6927 } 6928 6929 /* However, if there's no other matchset, add the RSSI one */ 6930 if (!n_match_sets && default_match_rssi != NL80211_SCAN_RSSI_THOLD_OFF) 6931 n_match_sets = 1; 6932 6933 if (n_match_sets > wiphy->max_match_sets) 6934 return ERR_PTR(-EINVAL); 6935 6936 if (attrs[NL80211_ATTR_IE]) 6937 ie_len = nla_len(attrs[NL80211_ATTR_IE]); 6938 else 6939 ie_len = 0; 6940 6941 if (ie_len > wiphy->max_sched_scan_ie_len) 6942 return ERR_PTR(-EINVAL); 6943 6944 if (attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) { 6945 /* 6946 * NL80211_ATTR_SCHED_SCAN_INTERVAL must not be specified since 6947 * each scan plan already specifies its own interval 6948 */ 6949 if (attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]) 6950 return ERR_PTR(-EINVAL); 6951 6952 nla_for_each_nested(attr, 6953 attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp) 6954 n_plans++; 6955 } else { 6956 /* 6957 * The scan interval attribute is kept for backward 6958 * compatibility. If no scan plans are specified and sched scan 6959 * interval is specified, one scan plan will be set with this 6960 * scan interval and infinite number of iterations. 6961 */ 6962 if (!attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]) 6963 return ERR_PTR(-EINVAL); 6964 6965 n_plans = 1; 6966 } 6967 6968 if (!n_plans || n_plans > wiphy->max_sched_scan_plans) 6969 return ERR_PTR(-EINVAL); 6970 6971 request = kzalloc(sizeof(*request) 6972 + sizeof(*request->ssids) * n_ssids 6973 + sizeof(*request->match_sets) * n_match_sets 6974 + sizeof(*request->scan_plans) * n_plans 6975 + sizeof(*request->channels) * n_channels 6976 + ie_len, GFP_KERNEL); 6977 if (!request) 6978 return ERR_PTR(-ENOMEM); 6979 6980 if (n_ssids) 6981 request->ssids = (void *)&request->channels[n_channels]; 6982 request->n_ssids = n_ssids; 6983 if (ie_len) { 6984 if (n_ssids) 6985 request->ie = (void *)(request->ssids + n_ssids); 6986 else 6987 request->ie = (void *)(request->channels + n_channels); 6988 } 6989 6990 if (n_match_sets) { 6991 if (request->ie) 6992 request->match_sets = (void *)(request->ie + ie_len); 6993 else if (n_ssids) 6994 request->match_sets = 6995 (void *)(request->ssids + n_ssids); 6996 else 6997 request->match_sets = 6998 (void *)(request->channels + n_channels); 6999 } 7000 request->n_match_sets = n_match_sets; 7001 7002 if (n_match_sets) 7003 request->scan_plans = (void *)(request->match_sets + 7004 n_match_sets); 7005 else if (request->ie) 7006 request->scan_plans = (void *)(request->ie + ie_len); 7007 else if (n_ssids) 7008 request->scan_plans = (void *)(request->ssids + n_ssids); 7009 else 7010 request->scan_plans = (void *)(request->channels + n_channels); 7011 7012 request->n_scan_plans = n_plans; 7013 7014 i = 0; 7015 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) { 7016 /* user specified, bail out if channel not found */ 7017 nla_for_each_nested(attr, 7018 attrs[NL80211_ATTR_SCAN_FREQUENCIES], 7019 tmp) { 7020 struct ieee80211_channel *chan; 7021 7022 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr)); 7023 7024 if (!chan) { 7025 err = -EINVAL; 7026 goto out_free; 7027 } 7028 7029 /* ignore disabled channels */ 7030 if (chan->flags & IEEE80211_CHAN_DISABLED) 7031 continue; 7032 7033 request->channels[i] = chan; 7034 i++; 7035 } 7036 } else { 7037 /* all channels */ 7038 for (band = 0; band < NUM_NL80211_BANDS; band++) { 7039 int j; 7040 7041 if (!wiphy->bands[band]) 7042 continue; 7043 for (j = 0; j < wiphy->bands[band]->n_channels; j++) { 7044 struct ieee80211_channel *chan; 7045 7046 chan = &wiphy->bands[band]->channels[j]; 7047 7048 if (chan->flags & IEEE80211_CHAN_DISABLED) 7049 continue; 7050 7051 request->channels[i] = chan; 7052 i++; 7053 } 7054 } 7055 } 7056 7057 if (!i) { 7058 err = -EINVAL; 7059 goto out_free; 7060 } 7061 7062 request->n_channels = i; 7063 7064 i = 0; 7065 if (n_ssids) { 7066 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS], 7067 tmp) { 7068 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) { 7069 err = -EINVAL; 7070 goto out_free; 7071 } 7072 request->ssids[i].ssid_len = nla_len(attr); 7073 memcpy(request->ssids[i].ssid, nla_data(attr), 7074 nla_len(attr)); 7075 i++; 7076 } 7077 } 7078 7079 i = 0; 7080 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) { 7081 nla_for_each_nested(attr, 7082 attrs[NL80211_ATTR_SCHED_SCAN_MATCH], 7083 tmp) { 7084 struct nlattr *ssid, *rssi; 7085 7086 err = nla_parse_nested(tb, 7087 NL80211_SCHED_SCAN_MATCH_ATTR_MAX, 7088 attr, nl80211_match_policy); 7089 if (err) 7090 goto out_free; 7091 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID]; 7092 if (ssid) { 7093 if (WARN_ON(i >= n_match_sets)) { 7094 /* this indicates a programming error, 7095 * the loop above should have verified 7096 * things properly 7097 */ 7098 err = -EINVAL; 7099 goto out_free; 7100 } 7101 7102 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) { 7103 err = -EINVAL; 7104 goto out_free; 7105 } 7106 memcpy(request->match_sets[i].ssid.ssid, 7107 nla_data(ssid), nla_len(ssid)); 7108 request->match_sets[i].ssid.ssid_len = 7109 nla_len(ssid); 7110 /* special attribute - old implementation w/a */ 7111 request->match_sets[i].rssi_thold = 7112 default_match_rssi; 7113 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI]; 7114 if (rssi) 7115 request->match_sets[i].rssi_thold = 7116 nla_get_s32(rssi); 7117 } 7118 i++; 7119 } 7120 7121 /* there was no other matchset, so the RSSI one is alone */ 7122 if (i == 0 && n_match_sets) 7123 request->match_sets[0].rssi_thold = default_match_rssi; 7124 7125 request->min_rssi_thold = INT_MAX; 7126 for (i = 0; i < n_match_sets; i++) 7127 request->min_rssi_thold = 7128 min(request->match_sets[i].rssi_thold, 7129 request->min_rssi_thold); 7130 } else { 7131 request->min_rssi_thold = NL80211_SCAN_RSSI_THOLD_OFF; 7132 } 7133 7134 if (ie_len) { 7135 request->ie_len = ie_len; 7136 memcpy((void *)request->ie, 7137 nla_data(attrs[NL80211_ATTR_IE]), 7138 request->ie_len); 7139 } 7140 7141 if (attrs[NL80211_ATTR_SCAN_FLAGS]) { 7142 request->flags = nla_get_u32( 7143 attrs[NL80211_ATTR_SCAN_FLAGS]); 7144 if ((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) && 7145 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) { 7146 err = -EOPNOTSUPP; 7147 goto out_free; 7148 } 7149 7150 if (request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) { 7151 u32 flg = NL80211_FEATURE_SCHED_SCAN_RANDOM_MAC_ADDR; 7152 7153 if (!wdev) /* must be net-detect */ 7154 flg = NL80211_FEATURE_ND_RANDOM_MAC_ADDR; 7155 7156 if (!(wiphy->features & flg)) { 7157 err = -EOPNOTSUPP; 7158 goto out_free; 7159 } 7160 7161 if (wdev && wdev->current_bss) { 7162 err = -EOPNOTSUPP; 7163 goto out_free; 7164 } 7165 7166 err = nl80211_parse_random_mac(attrs, request->mac_addr, 7167 request->mac_addr_mask); 7168 if (err) 7169 goto out_free; 7170 } 7171 } 7172 7173 if (attrs[NL80211_ATTR_SCHED_SCAN_DELAY]) 7174 request->delay = 7175 nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_DELAY]); 7176 7177 err = nl80211_parse_sched_scan_plans(wiphy, n_plans, request, attrs); 7178 if (err) 7179 goto out_free; 7180 7181 request->scan_start = jiffies; 7182 7183 return request; 7184 7185 out_free: 7186 kfree(request); 7187 return ERR_PTR(err); 7188 } 7189 7190 static int nl80211_start_sched_scan(struct sk_buff *skb, 7191 struct genl_info *info) 7192 { 7193 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7194 struct net_device *dev = info->user_ptr[1]; 7195 struct wireless_dev *wdev = dev->ieee80211_ptr; 7196 struct cfg80211_sched_scan_request *sched_scan_req; 7197 int err; 7198 7199 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) || 7200 !rdev->ops->sched_scan_start) 7201 return -EOPNOTSUPP; 7202 7203 if (rdev->sched_scan_req) 7204 return -EINPROGRESS; 7205 7206 sched_scan_req = nl80211_parse_sched_scan(&rdev->wiphy, wdev, 7207 info->attrs); 7208 7209 err = PTR_ERR_OR_ZERO(sched_scan_req); 7210 if (err) 7211 goto out_err; 7212 7213 err = rdev_sched_scan_start(rdev, dev, sched_scan_req); 7214 if (err) 7215 goto out_free; 7216 7217 sched_scan_req->dev = dev; 7218 sched_scan_req->wiphy = &rdev->wiphy; 7219 7220 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) 7221 sched_scan_req->owner_nlportid = info->snd_portid; 7222 7223 rcu_assign_pointer(rdev->sched_scan_req, sched_scan_req); 7224 7225 nl80211_send_sched_scan(rdev, dev, 7226 NL80211_CMD_START_SCHED_SCAN); 7227 return 0; 7228 7229 out_free: 7230 kfree(sched_scan_req); 7231 out_err: 7232 return err; 7233 } 7234 7235 static int nl80211_stop_sched_scan(struct sk_buff *skb, 7236 struct genl_info *info) 7237 { 7238 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7239 7240 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) || 7241 !rdev->ops->sched_scan_stop) 7242 return -EOPNOTSUPP; 7243 7244 return __cfg80211_stop_sched_scan(rdev, false); 7245 } 7246 7247 static int nl80211_start_radar_detection(struct sk_buff *skb, 7248 struct genl_info *info) 7249 { 7250 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7251 struct net_device *dev = info->user_ptr[1]; 7252 struct wireless_dev *wdev = dev->ieee80211_ptr; 7253 struct cfg80211_chan_def chandef; 7254 enum nl80211_dfs_regions dfs_region; 7255 unsigned int cac_time_ms; 7256 int err; 7257 7258 dfs_region = reg_get_dfs_region(wdev->wiphy); 7259 if (dfs_region == NL80211_DFS_UNSET) 7260 return -EINVAL; 7261 7262 err = nl80211_parse_chandef(rdev, info, &chandef); 7263 if (err) 7264 return err; 7265 7266 if (netif_carrier_ok(dev)) 7267 return -EBUSY; 7268 7269 if (wdev->cac_started) 7270 return -EBUSY; 7271 7272 err = cfg80211_chandef_dfs_required(wdev->wiphy, &chandef, 7273 wdev->iftype); 7274 if (err < 0) 7275 return err; 7276 7277 if (err == 0) 7278 return -EINVAL; 7279 7280 if (!cfg80211_chandef_dfs_usable(wdev->wiphy, &chandef)) 7281 return -EINVAL; 7282 7283 if (!rdev->ops->start_radar_detection) 7284 return -EOPNOTSUPP; 7285 7286 cac_time_ms = cfg80211_chandef_dfs_cac_time(&rdev->wiphy, &chandef); 7287 if (WARN_ON(!cac_time_ms)) 7288 cac_time_ms = IEEE80211_DFS_MIN_CAC_TIME_MS; 7289 7290 err = rdev_start_radar_detection(rdev, dev, &chandef, cac_time_ms); 7291 if (!err) { 7292 wdev->chandef = chandef; 7293 wdev->cac_started = true; 7294 wdev->cac_start_time = jiffies; 7295 wdev->cac_time_ms = cac_time_ms; 7296 } 7297 return err; 7298 } 7299 7300 static int nl80211_channel_switch(struct sk_buff *skb, struct genl_info *info) 7301 { 7302 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7303 struct net_device *dev = info->user_ptr[1]; 7304 struct wireless_dev *wdev = dev->ieee80211_ptr; 7305 struct cfg80211_csa_settings params; 7306 /* csa_attrs is defined static to avoid waste of stack size - this 7307 * function is called under RTNL lock, so this should not be a problem. 7308 */ 7309 static struct nlattr *csa_attrs[NL80211_ATTR_MAX+1]; 7310 int err; 7311 bool need_new_beacon = false; 7312 int len, i; 7313 u32 cs_count; 7314 7315 if (!rdev->ops->channel_switch || 7316 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH)) 7317 return -EOPNOTSUPP; 7318 7319 switch (dev->ieee80211_ptr->iftype) { 7320 case NL80211_IFTYPE_AP: 7321 case NL80211_IFTYPE_P2P_GO: 7322 need_new_beacon = true; 7323 7324 /* useless if AP is not running */ 7325 if (!wdev->beacon_interval) 7326 return -ENOTCONN; 7327 break; 7328 case NL80211_IFTYPE_ADHOC: 7329 if (!wdev->ssid_len) 7330 return -ENOTCONN; 7331 break; 7332 case NL80211_IFTYPE_MESH_POINT: 7333 if (!wdev->mesh_id_len) 7334 return -ENOTCONN; 7335 break; 7336 default: 7337 return -EOPNOTSUPP; 7338 } 7339 7340 memset(¶ms, 0, sizeof(params)); 7341 7342 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] || 7343 !info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]) 7344 return -EINVAL; 7345 7346 /* only important for AP, IBSS and mesh create IEs internally */ 7347 if (need_new_beacon && !info->attrs[NL80211_ATTR_CSA_IES]) 7348 return -EINVAL; 7349 7350 /* Even though the attribute is u32, the specification says 7351 * u8, so let's make sure we don't overflow. 7352 */ 7353 cs_count = nla_get_u32(info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]); 7354 if (cs_count > 255) 7355 return -EINVAL; 7356 7357 params.count = cs_count; 7358 7359 if (!need_new_beacon) 7360 goto skip_beacons; 7361 7362 err = nl80211_parse_beacon(info->attrs, ¶ms.beacon_after); 7363 if (err) 7364 return err; 7365 7366 err = nla_parse_nested(csa_attrs, NL80211_ATTR_MAX, 7367 info->attrs[NL80211_ATTR_CSA_IES], 7368 nl80211_policy); 7369 if (err) 7370 return err; 7371 7372 err = nl80211_parse_beacon(csa_attrs, ¶ms.beacon_csa); 7373 if (err) 7374 return err; 7375 7376 if (!csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]) 7377 return -EINVAL; 7378 7379 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]); 7380 if (!len || (len % sizeof(u16))) 7381 return -EINVAL; 7382 7383 params.n_counter_offsets_beacon = len / sizeof(u16); 7384 if (rdev->wiphy.max_num_csa_counters && 7385 (params.n_counter_offsets_beacon > 7386 rdev->wiphy.max_num_csa_counters)) 7387 return -EINVAL; 7388 7389 params.counter_offsets_beacon = 7390 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]); 7391 7392 /* sanity checks - counters should fit and be the same */ 7393 for (i = 0; i < params.n_counter_offsets_beacon; i++) { 7394 u16 offset = params.counter_offsets_beacon[i]; 7395 7396 if (offset >= params.beacon_csa.tail_len) 7397 return -EINVAL; 7398 7399 if (params.beacon_csa.tail[offset] != params.count) 7400 return -EINVAL; 7401 } 7402 7403 if (csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]) { 7404 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]); 7405 if (!len || (len % sizeof(u16))) 7406 return -EINVAL; 7407 7408 params.n_counter_offsets_presp = len / sizeof(u16); 7409 if (rdev->wiphy.max_num_csa_counters && 7410 (params.n_counter_offsets_presp > 7411 rdev->wiphy.max_num_csa_counters)) 7412 return -EINVAL; 7413 7414 params.counter_offsets_presp = 7415 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]); 7416 7417 /* sanity checks - counters should fit and be the same */ 7418 for (i = 0; i < params.n_counter_offsets_presp; i++) { 7419 u16 offset = params.counter_offsets_presp[i]; 7420 7421 if (offset >= params.beacon_csa.probe_resp_len) 7422 return -EINVAL; 7423 7424 if (params.beacon_csa.probe_resp[offset] != 7425 params.count) 7426 return -EINVAL; 7427 } 7428 } 7429 7430 skip_beacons: 7431 err = nl80211_parse_chandef(rdev, info, ¶ms.chandef); 7432 if (err) 7433 return err; 7434 7435 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, ¶ms.chandef, 7436 wdev->iftype)) 7437 return -EINVAL; 7438 7439 err = cfg80211_chandef_dfs_required(wdev->wiphy, 7440 ¶ms.chandef, 7441 wdev->iftype); 7442 if (err < 0) 7443 return err; 7444 7445 if (err > 0) 7446 params.radar_required = true; 7447 7448 if (info->attrs[NL80211_ATTR_CH_SWITCH_BLOCK_TX]) 7449 params.block_tx = true; 7450 7451 wdev_lock(wdev); 7452 err = rdev_channel_switch(rdev, dev, ¶ms); 7453 wdev_unlock(wdev); 7454 7455 return err; 7456 } 7457 7458 static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb, 7459 u32 seq, int flags, 7460 struct cfg80211_registered_device *rdev, 7461 struct wireless_dev *wdev, 7462 struct cfg80211_internal_bss *intbss) 7463 { 7464 struct cfg80211_bss *res = &intbss->pub; 7465 const struct cfg80211_bss_ies *ies; 7466 void *hdr; 7467 struct nlattr *bss; 7468 7469 ASSERT_WDEV_LOCK(wdev); 7470 7471 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags, 7472 NL80211_CMD_NEW_SCAN_RESULTS); 7473 if (!hdr) 7474 return -1; 7475 7476 genl_dump_check_consistent(cb, hdr, &nl80211_fam); 7477 7478 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation)) 7479 goto nla_put_failure; 7480 if (wdev->netdev && 7481 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex)) 7482 goto nla_put_failure; 7483 if (nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 7484 NL80211_ATTR_PAD)) 7485 goto nla_put_failure; 7486 7487 bss = nla_nest_start(msg, NL80211_ATTR_BSS); 7488 if (!bss) 7489 goto nla_put_failure; 7490 if ((!is_zero_ether_addr(res->bssid) && 7491 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid))) 7492 goto nla_put_failure; 7493 7494 rcu_read_lock(); 7495 /* indicate whether we have probe response data or not */ 7496 if (rcu_access_pointer(res->proberesp_ies) && 7497 nla_put_flag(msg, NL80211_BSS_PRESP_DATA)) 7498 goto fail_unlock_rcu; 7499 7500 /* this pointer prefers to be pointed to probe response data 7501 * but is always valid 7502 */ 7503 ies = rcu_dereference(res->ies); 7504 if (ies) { 7505 if (nla_put_u64_64bit(msg, NL80211_BSS_TSF, ies->tsf, 7506 NL80211_BSS_PAD)) 7507 goto fail_unlock_rcu; 7508 if (ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS, 7509 ies->len, ies->data)) 7510 goto fail_unlock_rcu; 7511 } 7512 7513 /* and this pointer is always (unless driver didn't know) beacon data */ 7514 ies = rcu_dereference(res->beacon_ies); 7515 if (ies && ies->from_beacon) { 7516 if (nla_put_u64_64bit(msg, NL80211_BSS_BEACON_TSF, ies->tsf, 7517 NL80211_BSS_PAD)) 7518 goto fail_unlock_rcu; 7519 if (ies->len && nla_put(msg, NL80211_BSS_BEACON_IES, 7520 ies->len, ies->data)) 7521 goto fail_unlock_rcu; 7522 } 7523 rcu_read_unlock(); 7524 7525 if (res->beacon_interval && 7526 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval)) 7527 goto nla_put_failure; 7528 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) || 7529 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) || 7530 nla_put_u32(msg, NL80211_BSS_CHAN_WIDTH, res->scan_width) || 7531 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO, 7532 jiffies_to_msecs(jiffies - intbss->ts))) 7533 goto nla_put_failure; 7534 7535 if (intbss->parent_tsf && 7536 (nla_put_u64_64bit(msg, NL80211_BSS_PARENT_TSF, 7537 intbss->parent_tsf, NL80211_BSS_PAD) || 7538 nla_put(msg, NL80211_BSS_PARENT_BSSID, ETH_ALEN, 7539 intbss->parent_bssid))) 7540 goto nla_put_failure; 7541 7542 if (intbss->ts_boottime && 7543 nla_put_u64_64bit(msg, NL80211_BSS_LAST_SEEN_BOOTTIME, 7544 intbss->ts_boottime, NL80211_BSS_PAD)) 7545 goto nla_put_failure; 7546 7547 switch (rdev->wiphy.signal_type) { 7548 case CFG80211_SIGNAL_TYPE_MBM: 7549 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal)) 7550 goto nla_put_failure; 7551 break; 7552 case CFG80211_SIGNAL_TYPE_UNSPEC: 7553 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal)) 7554 goto nla_put_failure; 7555 break; 7556 default: 7557 break; 7558 } 7559 7560 switch (wdev->iftype) { 7561 case NL80211_IFTYPE_P2P_CLIENT: 7562 case NL80211_IFTYPE_STATION: 7563 if (intbss == wdev->current_bss && 7564 nla_put_u32(msg, NL80211_BSS_STATUS, 7565 NL80211_BSS_STATUS_ASSOCIATED)) 7566 goto nla_put_failure; 7567 break; 7568 case NL80211_IFTYPE_ADHOC: 7569 if (intbss == wdev->current_bss && 7570 nla_put_u32(msg, NL80211_BSS_STATUS, 7571 NL80211_BSS_STATUS_IBSS_JOINED)) 7572 goto nla_put_failure; 7573 break; 7574 default: 7575 break; 7576 } 7577 7578 nla_nest_end(msg, bss); 7579 7580 genlmsg_end(msg, hdr); 7581 return 0; 7582 7583 fail_unlock_rcu: 7584 rcu_read_unlock(); 7585 nla_put_failure: 7586 genlmsg_cancel(msg, hdr); 7587 return -EMSGSIZE; 7588 } 7589 7590 static int nl80211_dump_scan(struct sk_buff *skb, struct netlink_callback *cb) 7591 { 7592 struct cfg80211_registered_device *rdev; 7593 struct cfg80211_internal_bss *scan; 7594 struct wireless_dev *wdev; 7595 int start = cb->args[2], idx = 0; 7596 int err; 7597 7598 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 7599 if (err) 7600 return err; 7601 7602 wdev_lock(wdev); 7603 spin_lock_bh(&rdev->bss_lock); 7604 cfg80211_bss_expire(rdev); 7605 7606 cb->seq = rdev->bss_generation; 7607 7608 list_for_each_entry(scan, &rdev->bss_list, list) { 7609 if (++idx <= start) 7610 continue; 7611 if (nl80211_send_bss(skb, cb, 7612 cb->nlh->nlmsg_seq, NLM_F_MULTI, 7613 rdev, wdev, scan) < 0) { 7614 idx--; 7615 break; 7616 } 7617 } 7618 7619 spin_unlock_bh(&rdev->bss_lock); 7620 wdev_unlock(wdev); 7621 7622 cb->args[2] = idx; 7623 nl80211_finish_wdev_dump(rdev); 7624 7625 return skb->len; 7626 } 7627 7628 static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq, 7629 int flags, struct net_device *dev, 7630 bool allow_radio_stats, 7631 struct survey_info *survey) 7632 { 7633 void *hdr; 7634 struct nlattr *infoattr; 7635 7636 /* skip radio stats if userspace didn't request them */ 7637 if (!survey->channel && !allow_radio_stats) 7638 return 0; 7639 7640 hdr = nl80211hdr_put(msg, portid, seq, flags, 7641 NL80211_CMD_NEW_SURVEY_RESULTS); 7642 if (!hdr) 7643 return -ENOMEM; 7644 7645 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex)) 7646 goto nla_put_failure; 7647 7648 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO); 7649 if (!infoattr) 7650 goto nla_put_failure; 7651 7652 if (survey->channel && 7653 nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY, 7654 survey->channel->center_freq)) 7655 goto nla_put_failure; 7656 7657 if ((survey->filled & SURVEY_INFO_NOISE_DBM) && 7658 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise)) 7659 goto nla_put_failure; 7660 if ((survey->filled & SURVEY_INFO_IN_USE) && 7661 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE)) 7662 goto nla_put_failure; 7663 if ((survey->filled & SURVEY_INFO_TIME) && 7664 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME, 7665 survey->time, NL80211_SURVEY_INFO_PAD)) 7666 goto nla_put_failure; 7667 if ((survey->filled & SURVEY_INFO_TIME_BUSY) && 7668 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_BUSY, 7669 survey->time_busy, NL80211_SURVEY_INFO_PAD)) 7670 goto nla_put_failure; 7671 if ((survey->filled & SURVEY_INFO_TIME_EXT_BUSY) && 7672 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_EXT_BUSY, 7673 survey->time_ext_busy, NL80211_SURVEY_INFO_PAD)) 7674 goto nla_put_failure; 7675 if ((survey->filled & SURVEY_INFO_TIME_RX) && 7676 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_RX, 7677 survey->time_rx, NL80211_SURVEY_INFO_PAD)) 7678 goto nla_put_failure; 7679 if ((survey->filled & SURVEY_INFO_TIME_TX) && 7680 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_TX, 7681 survey->time_tx, NL80211_SURVEY_INFO_PAD)) 7682 goto nla_put_failure; 7683 if ((survey->filled & SURVEY_INFO_TIME_SCAN) && 7684 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_SCAN, 7685 survey->time_scan, NL80211_SURVEY_INFO_PAD)) 7686 goto nla_put_failure; 7687 7688 nla_nest_end(msg, infoattr); 7689 7690 genlmsg_end(msg, hdr); 7691 return 0; 7692 7693 nla_put_failure: 7694 genlmsg_cancel(msg, hdr); 7695 return -EMSGSIZE; 7696 } 7697 7698 static int nl80211_dump_survey(struct sk_buff *skb, struct netlink_callback *cb) 7699 { 7700 struct nlattr **attrbuf = genl_family_attrbuf(&nl80211_fam); 7701 struct survey_info survey; 7702 struct cfg80211_registered_device *rdev; 7703 struct wireless_dev *wdev; 7704 int survey_idx = cb->args[2]; 7705 int res; 7706 bool radio_stats; 7707 7708 res = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 7709 if (res) 7710 return res; 7711 7712 /* prepare_wdev_dump parsed the attributes */ 7713 radio_stats = attrbuf[NL80211_ATTR_SURVEY_RADIO_STATS]; 7714 7715 if (!wdev->netdev) { 7716 res = -EINVAL; 7717 goto out_err; 7718 } 7719 7720 if (!rdev->ops->dump_survey) { 7721 res = -EOPNOTSUPP; 7722 goto out_err; 7723 } 7724 7725 while (1) { 7726 res = rdev_dump_survey(rdev, wdev->netdev, survey_idx, &survey); 7727 if (res == -ENOENT) 7728 break; 7729 if (res) 7730 goto out_err; 7731 7732 /* don't send disabled channels, but do send non-channel data */ 7733 if (survey.channel && 7734 survey.channel->flags & IEEE80211_CHAN_DISABLED) { 7735 survey_idx++; 7736 continue; 7737 } 7738 7739 if (nl80211_send_survey(skb, 7740 NETLINK_CB(cb->skb).portid, 7741 cb->nlh->nlmsg_seq, NLM_F_MULTI, 7742 wdev->netdev, radio_stats, &survey) < 0) 7743 goto out; 7744 survey_idx++; 7745 } 7746 7747 out: 7748 cb->args[2] = survey_idx; 7749 res = skb->len; 7750 out_err: 7751 nl80211_finish_wdev_dump(rdev); 7752 return res; 7753 } 7754 7755 static bool nl80211_valid_wpa_versions(u32 wpa_versions) 7756 { 7757 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 | 7758 NL80211_WPA_VERSION_2)); 7759 } 7760 7761 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info) 7762 { 7763 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7764 struct net_device *dev = info->user_ptr[1]; 7765 struct ieee80211_channel *chan; 7766 const u8 *bssid, *ssid, *ie = NULL, *auth_data = NULL; 7767 int err, ssid_len, ie_len = 0, auth_data_len = 0; 7768 enum nl80211_auth_type auth_type; 7769 struct key_parse key; 7770 bool local_state_change; 7771 7772 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 7773 return -EINVAL; 7774 7775 if (!info->attrs[NL80211_ATTR_MAC]) 7776 return -EINVAL; 7777 7778 if (!info->attrs[NL80211_ATTR_AUTH_TYPE]) 7779 return -EINVAL; 7780 7781 if (!info->attrs[NL80211_ATTR_SSID]) 7782 return -EINVAL; 7783 7784 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ]) 7785 return -EINVAL; 7786 7787 err = nl80211_parse_key(info, &key); 7788 if (err) 7789 return err; 7790 7791 if (key.idx >= 0) { 7792 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP) 7793 return -EINVAL; 7794 if (!key.p.key || !key.p.key_len) 7795 return -EINVAL; 7796 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 || 7797 key.p.key_len != WLAN_KEY_LEN_WEP40) && 7798 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 || 7799 key.p.key_len != WLAN_KEY_LEN_WEP104)) 7800 return -EINVAL; 7801 if (key.idx > 3) 7802 return -EINVAL; 7803 } else { 7804 key.p.key_len = 0; 7805 key.p.key = NULL; 7806 } 7807 7808 if (key.idx >= 0) { 7809 int i; 7810 bool ok = false; 7811 7812 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) { 7813 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) { 7814 ok = true; 7815 break; 7816 } 7817 } 7818 if (!ok) 7819 return -EINVAL; 7820 } 7821 7822 if (!rdev->ops->auth) 7823 return -EOPNOTSUPP; 7824 7825 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 7826 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 7827 return -EOPNOTSUPP; 7828 7829 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 7830 chan = nl80211_get_valid_chan(&rdev->wiphy, 7831 info->attrs[NL80211_ATTR_WIPHY_FREQ]); 7832 if (!chan) 7833 return -EINVAL; 7834 7835 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 7836 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]); 7837 7838 if (info->attrs[NL80211_ATTR_IE]) { 7839 ie = nla_data(info->attrs[NL80211_ATTR_IE]); 7840 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 7841 } 7842 7843 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]); 7844 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE)) 7845 return -EINVAL; 7846 7847 if ((auth_type == NL80211_AUTHTYPE_SAE || 7848 auth_type == NL80211_AUTHTYPE_FILS_SK || 7849 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS || 7850 auth_type == NL80211_AUTHTYPE_FILS_PK) && 7851 !info->attrs[NL80211_ATTR_AUTH_DATA]) 7852 return -EINVAL; 7853 7854 if (info->attrs[NL80211_ATTR_AUTH_DATA]) { 7855 if (auth_type != NL80211_AUTHTYPE_SAE && 7856 auth_type != NL80211_AUTHTYPE_FILS_SK && 7857 auth_type != NL80211_AUTHTYPE_FILS_SK_PFS && 7858 auth_type != NL80211_AUTHTYPE_FILS_PK) 7859 return -EINVAL; 7860 auth_data = nla_data(info->attrs[NL80211_ATTR_AUTH_DATA]); 7861 auth_data_len = nla_len(info->attrs[NL80211_ATTR_AUTH_DATA]); 7862 /* need to include at least Auth Transaction and Status Code */ 7863 if (auth_data_len < 4) 7864 return -EINVAL; 7865 } 7866 7867 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE]; 7868 7869 /* 7870 * Since we no longer track auth state, ignore 7871 * requests to only change local state. 7872 */ 7873 if (local_state_change) 7874 return 0; 7875 7876 wdev_lock(dev->ieee80211_ptr); 7877 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid, 7878 ssid, ssid_len, ie, ie_len, 7879 key.p.key, key.p.key_len, key.idx, 7880 auth_data, auth_data_len); 7881 wdev_unlock(dev->ieee80211_ptr); 7882 return err; 7883 } 7884 7885 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev, 7886 struct genl_info *info, 7887 struct cfg80211_crypto_settings *settings, 7888 int cipher_limit) 7889 { 7890 memset(settings, 0, sizeof(*settings)); 7891 7892 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT]; 7893 7894 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) { 7895 u16 proto; 7896 7897 proto = nla_get_u16( 7898 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]); 7899 settings->control_port_ethertype = cpu_to_be16(proto); 7900 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) && 7901 proto != ETH_P_PAE) 7902 return -EINVAL; 7903 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT]) 7904 settings->control_port_no_encrypt = true; 7905 } else 7906 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE); 7907 7908 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) { 7909 void *data; 7910 int len, i; 7911 7912 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]); 7913 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]); 7914 settings->n_ciphers_pairwise = len / sizeof(u32); 7915 7916 if (len % sizeof(u32)) 7917 return -EINVAL; 7918 7919 if (settings->n_ciphers_pairwise > cipher_limit) 7920 return -EINVAL; 7921 7922 memcpy(settings->ciphers_pairwise, data, len); 7923 7924 for (i = 0; i < settings->n_ciphers_pairwise; i++) 7925 if (!cfg80211_supported_cipher_suite( 7926 &rdev->wiphy, 7927 settings->ciphers_pairwise[i])) 7928 return -EINVAL; 7929 } 7930 7931 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) { 7932 settings->cipher_group = 7933 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]); 7934 if (!cfg80211_supported_cipher_suite(&rdev->wiphy, 7935 settings->cipher_group)) 7936 return -EINVAL; 7937 } 7938 7939 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) { 7940 settings->wpa_versions = 7941 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]); 7942 if (!nl80211_valid_wpa_versions(settings->wpa_versions)) 7943 return -EINVAL; 7944 } 7945 7946 if (info->attrs[NL80211_ATTR_AKM_SUITES]) { 7947 void *data; 7948 int len; 7949 7950 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]); 7951 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]); 7952 settings->n_akm_suites = len / sizeof(u32); 7953 7954 if (len % sizeof(u32)) 7955 return -EINVAL; 7956 7957 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES) 7958 return -EINVAL; 7959 7960 memcpy(settings->akm_suites, data, len); 7961 } 7962 7963 return 0; 7964 } 7965 7966 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info) 7967 { 7968 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7969 struct net_device *dev = info->user_ptr[1]; 7970 struct ieee80211_channel *chan; 7971 struct cfg80211_assoc_request req = {}; 7972 const u8 *bssid, *ssid; 7973 int err, ssid_len = 0; 7974 7975 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 7976 return -EINVAL; 7977 7978 if (!info->attrs[NL80211_ATTR_MAC] || 7979 !info->attrs[NL80211_ATTR_SSID] || 7980 !info->attrs[NL80211_ATTR_WIPHY_FREQ]) 7981 return -EINVAL; 7982 7983 if (!rdev->ops->assoc) 7984 return -EOPNOTSUPP; 7985 7986 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 7987 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 7988 return -EOPNOTSUPP; 7989 7990 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 7991 7992 chan = nl80211_get_valid_chan(&rdev->wiphy, 7993 info->attrs[NL80211_ATTR_WIPHY_FREQ]); 7994 if (!chan) 7995 return -EINVAL; 7996 7997 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 7998 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]); 7999 8000 if (info->attrs[NL80211_ATTR_IE]) { 8001 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8002 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8003 } 8004 8005 if (info->attrs[NL80211_ATTR_USE_MFP]) { 8006 enum nl80211_mfp mfp = 8007 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]); 8008 if (mfp == NL80211_MFP_REQUIRED) 8009 req.use_mfp = true; 8010 else if (mfp != NL80211_MFP_NO) 8011 return -EINVAL; 8012 } 8013 8014 if (info->attrs[NL80211_ATTR_PREV_BSSID]) 8015 req.prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]); 8016 8017 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT])) 8018 req.flags |= ASSOC_REQ_DISABLE_HT; 8019 8020 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8021 memcpy(&req.ht_capa_mask, 8022 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]), 8023 sizeof(req.ht_capa_mask)); 8024 8025 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) { 8026 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8027 return -EINVAL; 8028 memcpy(&req.ht_capa, 8029 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]), 8030 sizeof(req.ht_capa)); 8031 } 8032 8033 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT])) 8034 req.flags |= ASSOC_REQ_DISABLE_VHT; 8035 8036 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) 8037 memcpy(&req.vht_capa_mask, 8038 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]), 8039 sizeof(req.vht_capa_mask)); 8040 8041 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) { 8042 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) 8043 return -EINVAL; 8044 memcpy(&req.vht_capa, 8045 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]), 8046 sizeof(req.vht_capa)); 8047 } 8048 8049 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) { 8050 if (!((rdev->wiphy.features & 8051 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) && 8052 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) && 8053 !wiphy_ext_feature_isset(&rdev->wiphy, 8054 NL80211_EXT_FEATURE_RRM)) 8055 return -EINVAL; 8056 req.flags |= ASSOC_REQ_USE_RRM; 8057 } 8058 8059 if (info->attrs[NL80211_ATTR_FILS_KEK]) { 8060 req.fils_kek = nla_data(info->attrs[NL80211_ATTR_FILS_KEK]); 8061 req.fils_kek_len = nla_len(info->attrs[NL80211_ATTR_FILS_KEK]); 8062 if (!info->attrs[NL80211_ATTR_FILS_NONCES]) 8063 return -EINVAL; 8064 req.fils_nonces = 8065 nla_data(info->attrs[NL80211_ATTR_FILS_NONCES]); 8066 } 8067 8068 err = nl80211_crypto_settings(rdev, info, &req.crypto, 1); 8069 if (!err) { 8070 wdev_lock(dev->ieee80211_ptr); 8071 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, 8072 ssid, ssid_len, &req); 8073 wdev_unlock(dev->ieee80211_ptr); 8074 } 8075 8076 return err; 8077 } 8078 8079 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info) 8080 { 8081 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8082 struct net_device *dev = info->user_ptr[1]; 8083 const u8 *ie = NULL, *bssid; 8084 int ie_len = 0, err; 8085 u16 reason_code; 8086 bool local_state_change; 8087 8088 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8089 return -EINVAL; 8090 8091 if (!info->attrs[NL80211_ATTR_MAC]) 8092 return -EINVAL; 8093 8094 if (!info->attrs[NL80211_ATTR_REASON_CODE]) 8095 return -EINVAL; 8096 8097 if (!rdev->ops->deauth) 8098 return -EOPNOTSUPP; 8099 8100 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8101 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8102 return -EOPNOTSUPP; 8103 8104 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8105 8106 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]); 8107 if (reason_code == 0) { 8108 /* Reason Code 0 is reserved */ 8109 return -EINVAL; 8110 } 8111 8112 if (info->attrs[NL80211_ATTR_IE]) { 8113 ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8114 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8115 } 8116 8117 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE]; 8118 8119 wdev_lock(dev->ieee80211_ptr); 8120 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code, 8121 local_state_change); 8122 wdev_unlock(dev->ieee80211_ptr); 8123 return err; 8124 } 8125 8126 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info) 8127 { 8128 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8129 struct net_device *dev = info->user_ptr[1]; 8130 const u8 *ie = NULL, *bssid; 8131 int ie_len = 0, err; 8132 u16 reason_code; 8133 bool local_state_change; 8134 8135 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8136 return -EINVAL; 8137 8138 if (!info->attrs[NL80211_ATTR_MAC]) 8139 return -EINVAL; 8140 8141 if (!info->attrs[NL80211_ATTR_REASON_CODE]) 8142 return -EINVAL; 8143 8144 if (!rdev->ops->disassoc) 8145 return -EOPNOTSUPP; 8146 8147 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8148 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8149 return -EOPNOTSUPP; 8150 8151 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8152 8153 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]); 8154 if (reason_code == 0) { 8155 /* Reason Code 0 is reserved */ 8156 return -EINVAL; 8157 } 8158 8159 if (info->attrs[NL80211_ATTR_IE]) { 8160 ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8161 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8162 } 8163 8164 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE]; 8165 8166 wdev_lock(dev->ieee80211_ptr); 8167 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code, 8168 local_state_change); 8169 wdev_unlock(dev->ieee80211_ptr); 8170 return err; 8171 } 8172 8173 static bool 8174 nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev, 8175 int mcast_rate[NUM_NL80211_BANDS], 8176 int rateval) 8177 { 8178 struct wiphy *wiphy = &rdev->wiphy; 8179 bool found = false; 8180 int band, i; 8181 8182 for (band = 0; band < NUM_NL80211_BANDS; band++) { 8183 struct ieee80211_supported_band *sband; 8184 8185 sband = wiphy->bands[band]; 8186 if (!sband) 8187 continue; 8188 8189 for (i = 0; i < sband->n_bitrates; i++) { 8190 if (sband->bitrates[i].bitrate == rateval) { 8191 mcast_rate[band] = i + 1; 8192 found = true; 8193 break; 8194 } 8195 } 8196 } 8197 8198 return found; 8199 } 8200 8201 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info) 8202 { 8203 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8204 struct net_device *dev = info->user_ptr[1]; 8205 struct cfg80211_ibss_params ibss; 8206 struct wiphy *wiphy; 8207 struct cfg80211_cached_keys *connkeys = NULL; 8208 int err; 8209 8210 memset(&ibss, 0, sizeof(ibss)); 8211 8212 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8213 return -EINVAL; 8214 8215 if (!info->attrs[NL80211_ATTR_SSID] || 8216 !nla_len(info->attrs[NL80211_ATTR_SSID])) 8217 return -EINVAL; 8218 8219 ibss.beacon_interval = 100; 8220 8221 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) 8222 ibss.beacon_interval = 8223 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]); 8224 8225 err = cfg80211_validate_beacon_int(rdev, NL80211_IFTYPE_ADHOC, 8226 ibss.beacon_interval); 8227 if (err) 8228 return err; 8229 8230 if (!rdev->ops->join_ibss) 8231 return -EOPNOTSUPP; 8232 8233 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) 8234 return -EOPNOTSUPP; 8235 8236 wiphy = &rdev->wiphy; 8237 8238 if (info->attrs[NL80211_ATTR_MAC]) { 8239 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8240 8241 if (!is_valid_ether_addr(ibss.bssid)) 8242 return -EINVAL; 8243 } 8244 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 8245 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]); 8246 8247 if (info->attrs[NL80211_ATTR_IE]) { 8248 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8249 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8250 } 8251 8252 err = nl80211_parse_chandef(rdev, info, &ibss.chandef); 8253 if (err) 8254 return err; 8255 8256 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef, 8257 NL80211_IFTYPE_ADHOC)) 8258 return -EINVAL; 8259 8260 switch (ibss.chandef.width) { 8261 case NL80211_CHAN_WIDTH_5: 8262 case NL80211_CHAN_WIDTH_10: 8263 case NL80211_CHAN_WIDTH_20_NOHT: 8264 break; 8265 case NL80211_CHAN_WIDTH_20: 8266 case NL80211_CHAN_WIDTH_40: 8267 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS)) 8268 return -EINVAL; 8269 break; 8270 case NL80211_CHAN_WIDTH_80: 8271 case NL80211_CHAN_WIDTH_80P80: 8272 case NL80211_CHAN_WIDTH_160: 8273 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS)) 8274 return -EINVAL; 8275 if (!wiphy_ext_feature_isset(&rdev->wiphy, 8276 NL80211_EXT_FEATURE_VHT_IBSS)) 8277 return -EINVAL; 8278 break; 8279 default: 8280 return -EINVAL; 8281 } 8282 8283 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED]; 8284 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY]; 8285 8286 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) { 8287 u8 *rates = 8288 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 8289 int n_rates = 8290 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 8291 struct ieee80211_supported_band *sband = 8292 wiphy->bands[ibss.chandef.chan->band]; 8293 8294 err = ieee80211_get_ratemask(sband, rates, n_rates, 8295 &ibss.basic_rates); 8296 if (err) 8297 return err; 8298 } 8299 8300 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8301 memcpy(&ibss.ht_capa_mask, 8302 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]), 8303 sizeof(ibss.ht_capa_mask)); 8304 8305 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) { 8306 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8307 return -EINVAL; 8308 memcpy(&ibss.ht_capa, 8309 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]), 8310 sizeof(ibss.ht_capa)); 8311 } 8312 8313 if (info->attrs[NL80211_ATTR_MCAST_RATE] && 8314 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate, 8315 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]))) 8316 return -EINVAL; 8317 8318 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) { 8319 bool no_ht = false; 8320 8321 connkeys = nl80211_parse_connkeys(rdev, 8322 info->attrs[NL80211_ATTR_KEYS], 8323 &no_ht); 8324 if (IS_ERR(connkeys)) 8325 return PTR_ERR(connkeys); 8326 8327 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) && 8328 no_ht) { 8329 kzfree(connkeys); 8330 return -EINVAL; 8331 } 8332 } 8333 8334 ibss.control_port = 8335 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]); 8336 8337 ibss.userspace_handles_dfs = 8338 nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]); 8339 8340 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys); 8341 if (err) 8342 kzfree(connkeys); 8343 return err; 8344 } 8345 8346 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info) 8347 { 8348 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8349 struct net_device *dev = info->user_ptr[1]; 8350 8351 if (!rdev->ops->leave_ibss) 8352 return -EOPNOTSUPP; 8353 8354 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) 8355 return -EOPNOTSUPP; 8356 8357 return cfg80211_leave_ibss(rdev, dev, false); 8358 } 8359 8360 static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info) 8361 { 8362 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8363 struct net_device *dev = info->user_ptr[1]; 8364 int mcast_rate[NUM_NL80211_BANDS]; 8365 u32 nla_rate; 8366 int err; 8367 8368 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC && 8369 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT && 8370 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_OCB) 8371 return -EOPNOTSUPP; 8372 8373 if (!rdev->ops->set_mcast_rate) 8374 return -EOPNOTSUPP; 8375 8376 memset(mcast_rate, 0, sizeof(mcast_rate)); 8377 8378 if (!info->attrs[NL80211_ATTR_MCAST_RATE]) 8379 return -EINVAL; 8380 8381 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]); 8382 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate)) 8383 return -EINVAL; 8384 8385 err = rdev_set_mcast_rate(rdev, dev, mcast_rate); 8386 8387 return err; 8388 } 8389 8390 static struct sk_buff * 8391 __cfg80211_alloc_vendor_skb(struct cfg80211_registered_device *rdev, 8392 struct wireless_dev *wdev, int approxlen, 8393 u32 portid, u32 seq, enum nl80211_commands cmd, 8394 enum nl80211_attrs attr, 8395 const struct nl80211_vendor_cmd_info *info, 8396 gfp_t gfp) 8397 { 8398 struct sk_buff *skb; 8399 void *hdr; 8400 struct nlattr *data; 8401 8402 skb = nlmsg_new(approxlen + 100, gfp); 8403 if (!skb) 8404 return NULL; 8405 8406 hdr = nl80211hdr_put(skb, portid, seq, 0, cmd); 8407 if (!hdr) { 8408 kfree_skb(skb); 8409 return NULL; 8410 } 8411 8412 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx)) 8413 goto nla_put_failure; 8414 8415 if (info) { 8416 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_ID, 8417 info->vendor_id)) 8418 goto nla_put_failure; 8419 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_SUBCMD, 8420 info->subcmd)) 8421 goto nla_put_failure; 8422 } 8423 8424 if (wdev) { 8425 if (nla_put_u64_64bit(skb, NL80211_ATTR_WDEV, 8426 wdev_id(wdev), NL80211_ATTR_PAD)) 8427 goto nla_put_failure; 8428 if (wdev->netdev && 8429 nla_put_u32(skb, NL80211_ATTR_IFINDEX, 8430 wdev->netdev->ifindex)) 8431 goto nla_put_failure; 8432 } 8433 8434 data = nla_nest_start(skb, attr); 8435 if (!data) 8436 goto nla_put_failure; 8437 8438 ((void **)skb->cb)[0] = rdev; 8439 ((void **)skb->cb)[1] = hdr; 8440 ((void **)skb->cb)[2] = data; 8441 8442 return skb; 8443 8444 nla_put_failure: 8445 kfree_skb(skb); 8446 return NULL; 8447 } 8448 8449 struct sk_buff *__cfg80211_alloc_event_skb(struct wiphy *wiphy, 8450 struct wireless_dev *wdev, 8451 enum nl80211_commands cmd, 8452 enum nl80211_attrs attr, 8453 int vendor_event_idx, 8454 int approxlen, gfp_t gfp) 8455 { 8456 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 8457 const struct nl80211_vendor_cmd_info *info; 8458 8459 switch (cmd) { 8460 case NL80211_CMD_TESTMODE: 8461 if (WARN_ON(vendor_event_idx != -1)) 8462 return NULL; 8463 info = NULL; 8464 break; 8465 case NL80211_CMD_VENDOR: 8466 if (WARN_ON(vendor_event_idx < 0 || 8467 vendor_event_idx >= wiphy->n_vendor_events)) 8468 return NULL; 8469 info = &wiphy->vendor_events[vendor_event_idx]; 8470 break; 8471 default: 8472 WARN_ON(1); 8473 return NULL; 8474 } 8475 8476 return __cfg80211_alloc_vendor_skb(rdev, wdev, approxlen, 0, 0, 8477 cmd, attr, info, gfp); 8478 } 8479 EXPORT_SYMBOL(__cfg80211_alloc_event_skb); 8480 8481 void __cfg80211_send_event_skb(struct sk_buff *skb, gfp_t gfp) 8482 { 8483 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0]; 8484 void *hdr = ((void **)skb->cb)[1]; 8485 struct nlattr *data = ((void **)skb->cb)[2]; 8486 enum nl80211_multicast_groups mcgrp = NL80211_MCGRP_TESTMODE; 8487 8488 /* clear CB data for netlink core to own from now on */ 8489 memset(skb->cb, 0, sizeof(skb->cb)); 8490 8491 nla_nest_end(skb, data); 8492 genlmsg_end(skb, hdr); 8493 8494 if (data->nla_type == NL80211_ATTR_VENDOR_DATA) 8495 mcgrp = NL80211_MCGRP_VENDOR; 8496 8497 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), skb, 0, 8498 mcgrp, gfp); 8499 } 8500 EXPORT_SYMBOL(__cfg80211_send_event_skb); 8501 8502 #ifdef CONFIG_NL80211_TESTMODE 8503 static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info) 8504 { 8505 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8506 struct wireless_dev *wdev = 8507 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs); 8508 int err; 8509 8510 if (!rdev->ops->testmode_cmd) 8511 return -EOPNOTSUPP; 8512 8513 if (IS_ERR(wdev)) { 8514 err = PTR_ERR(wdev); 8515 if (err != -EINVAL) 8516 return err; 8517 wdev = NULL; 8518 } else if (wdev->wiphy != &rdev->wiphy) { 8519 return -EINVAL; 8520 } 8521 8522 if (!info->attrs[NL80211_ATTR_TESTDATA]) 8523 return -EINVAL; 8524 8525 rdev->cur_cmd_info = info; 8526 err = rdev_testmode_cmd(rdev, wdev, 8527 nla_data(info->attrs[NL80211_ATTR_TESTDATA]), 8528 nla_len(info->attrs[NL80211_ATTR_TESTDATA])); 8529 rdev->cur_cmd_info = NULL; 8530 8531 return err; 8532 } 8533 8534 static int nl80211_testmode_dump(struct sk_buff *skb, 8535 struct netlink_callback *cb) 8536 { 8537 struct cfg80211_registered_device *rdev; 8538 int err; 8539 long phy_idx; 8540 void *data = NULL; 8541 int data_len = 0; 8542 8543 rtnl_lock(); 8544 8545 if (cb->args[0]) { 8546 /* 8547 * 0 is a valid index, but not valid for args[0], 8548 * so we need to offset by 1. 8549 */ 8550 phy_idx = cb->args[0] - 1; 8551 } else { 8552 struct nlattr **attrbuf = genl_family_attrbuf(&nl80211_fam); 8553 8554 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, 8555 attrbuf, nl80211_fam.maxattr, nl80211_policy); 8556 if (err) 8557 goto out_err; 8558 8559 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf); 8560 if (IS_ERR(rdev)) { 8561 err = PTR_ERR(rdev); 8562 goto out_err; 8563 } 8564 phy_idx = rdev->wiphy_idx; 8565 rdev = NULL; 8566 8567 if (attrbuf[NL80211_ATTR_TESTDATA]) 8568 cb->args[1] = (long)attrbuf[NL80211_ATTR_TESTDATA]; 8569 } 8570 8571 if (cb->args[1]) { 8572 data = nla_data((void *)cb->args[1]); 8573 data_len = nla_len((void *)cb->args[1]); 8574 } 8575 8576 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx); 8577 if (!rdev) { 8578 err = -ENOENT; 8579 goto out_err; 8580 } 8581 8582 if (!rdev->ops->testmode_dump) { 8583 err = -EOPNOTSUPP; 8584 goto out_err; 8585 } 8586 8587 while (1) { 8588 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid, 8589 cb->nlh->nlmsg_seq, NLM_F_MULTI, 8590 NL80211_CMD_TESTMODE); 8591 struct nlattr *tmdata; 8592 8593 if (!hdr) 8594 break; 8595 8596 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) { 8597 genlmsg_cancel(skb, hdr); 8598 break; 8599 } 8600 8601 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA); 8602 if (!tmdata) { 8603 genlmsg_cancel(skb, hdr); 8604 break; 8605 } 8606 err = rdev_testmode_dump(rdev, skb, cb, data, data_len); 8607 nla_nest_end(skb, tmdata); 8608 8609 if (err == -ENOBUFS || err == -ENOENT) { 8610 genlmsg_cancel(skb, hdr); 8611 break; 8612 } else if (err) { 8613 genlmsg_cancel(skb, hdr); 8614 goto out_err; 8615 } 8616 8617 genlmsg_end(skb, hdr); 8618 } 8619 8620 err = skb->len; 8621 /* see above */ 8622 cb->args[0] = phy_idx + 1; 8623 out_err: 8624 rtnl_unlock(); 8625 return err; 8626 } 8627 #endif 8628 8629 static int nl80211_connect(struct sk_buff *skb, struct genl_info *info) 8630 { 8631 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8632 struct net_device *dev = info->user_ptr[1]; 8633 struct cfg80211_connect_params connect; 8634 struct wiphy *wiphy; 8635 struct cfg80211_cached_keys *connkeys = NULL; 8636 int err; 8637 8638 memset(&connect, 0, sizeof(connect)); 8639 8640 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8641 return -EINVAL; 8642 8643 if (!info->attrs[NL80211_ATTR_SSID] || 8644 !nla_len(info->attrs[NL80211_ATTR_SSID])) 8645 return -EINVAL; 8646 8647 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) { 8648 connect.auth_type = 8649 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]); 8650 if (!nl80211_valid_auth_type(rdev, connect.auth_type, 8651 NL80211_CMD_CONNECT)) 8652 return -EINVAL; 8653 } else 8654 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC; 8655 8656 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY]; 8657 8658 err = nl80211_crypto_settings(rdev, info, &connect.crypto, 8659 NL80211_MAX_NR_CIPHER_SUITES); 8660 if (err) 8661 return err; 8662 8663 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8664 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8665 return -EOPNOTSUPP; 8666 8667 wiphy = &rdev->wiphy; 8668 8669 connect.bg_scan_period = -1; 8670 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] && 8671 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) { 8672 connect.bg_scan_period = 8673 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]); 8674 } 8675 8676 if (info->attrs[NL80211_ATTR_MAC]) 8677 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8678 else if (info->attrs[NL80211_ATTR_MAC_HINT]) 8679 connect.bssid_hint = 8680 nla_data(info->attrs[NL80211_ATTR_MAC_HINT]); 8681 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 8682 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]); 8683 8684 if (info->attrs[NL80211_ATTR_IE]) { 8685 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8686 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8687 } 8688 8689 if (info->attrs[NL80211_ATTR_USE_MFP]) { 8690 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]); 8691 if (connect.mfp != NL80211_MFP_REQUIRED && 8692 connect.mfp != NL80211_MFP_NO) 8693 return -EINVAL; 8694 } else { 8695 connect.mfp = NL80211_MFP_NO; 8696 } 8697 8698 if (info->attrs[NL80211_ATTR_PREV_BSSID]) 8699 connect.prev_bssid = 8700 nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]); 8701 8702 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 8703 connect.channel = nl80211_get_valid_chan( 8704 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ]); 8705 if (!connect.channel) 8706 return -EINVAL; 8707 } else if (info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]) { 8708 connect.channel_hint = nl80211_get_valid_chan( 8709 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]); 8710 if (!connect.channel_hint) 8711 return -EINVAL; 8712 } 8713 8714 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) { 8715 connkeys = nl80211_parse_connkeys(rdev, 8716 info->attrs[NL80211_ATTR_KEYS], NULL); 8717 if (IS_ERR(connkeys)) 8718 return PTR_ERR(connkeys); 8719 } 8720 8721 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT])) 8722 connect.flags |= ASSOC_REQ_DISABLE_HT; 8723 8724 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8725 memcpy(&connect.ht_capa_mask, 8726 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]), 8727 sizeof(connect.ht_capa_mask)); 8728 8729 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) { 8730 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) { 8731 kzfree(connkeys); 8732 return -EINVAL; 8733 } 8734 memcpy(&connect.ht_capa, 8735 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]), 8736 sizeof(connect.ht_capa)); 8737 } 8738 8739 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT])) 8740 connect.flags |= ASSOC_REQ_DISABLE_VHT; 8741 8742 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) 8743 memcpy(&connect.vht_capa_mask, 8744 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]), 8745 sizeof(connect.vht_capa_mask)); 8746 8747 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) { 8748 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) { 8749 kzfree(connkeys); 8750 return -EINVAL; 8751 } 8752 memcpy(&connect.vht_capa, 8753 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]), 8754 sizeof(connect.vht_capa)); 8755 } 8756 8757 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) { 8758 if (!((rdev->wiphy.features & 8759 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) && 8760 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) && 8761 !wiphy_ext_feature_isset(&rdev->wiphy, 8762 NL80211_EXT_FEATURE_RRM)) { 8763 kzfree(connkeys); 8764 return -EINVAL; 8765 } 8766 connect.flags |= ASSOC_REQ_USE_RRM; 8767 } 8768 8769 connect.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]); 8770 if (connect.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ]) { 8771 kzfree(connkeys); 8772 return -EOPNOTSUPP; 8773 } 8774 8775 if (info->attrs[NL80211_ATTR_BSS_SELECT]) { 8776 /* bss selection makes no sense if bssid is set */ 8777 if (connect.bssid) { 8778 kzfree(connkeys); 8779 return -EINVAL; 8780 } 8781 8782 err = parse_bss_select(info->attrs[NL80211_ATTR_BSS_SELECT], 8783 wiphy, &connect.bss_select); 8784 if (err) { 8785 kzfree(connkeys); 8786 return err; 8787 } 8788 } 8789 8790 wdev_lock(dev->ieee80211_ptr); 8791 err = cfg80211_connect(rdev, dev, &connect, connkeys, 8792 connect.prev_bssid); 8793 wdev_unlock(dev->ieee80211_ptr); 8794 if (err) 8795 kzfree(connkeys); 8796 return err; 8797 } 8798 8799 static int nl80211_update_connect_params(struct sk_buff *skb, 8800 struct genl_info *info) 8801 { 8802 struct cfg80211_connect_params connect = {}; 8803 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8804 struct net_device *dev = info->user_ptr[1]; 8805 struct wireless_dev *wdev = dev->ieee80211_ptr; 8806 u32 changed = 0; 8807 int ret; 8808 8809 if (!rdev->ops->update_connect_params) 8810 return -EOPNOTSUPP; 8811 8812 if (info->attrs[NL80211_ATTR_IE]) { 8813 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8814 return -EINVAL; 8815 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8816 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8817 changed |= UPDATE_ASSOC_IES; 8818 } 8819 8820 wdev_lock(dev->ieee80211_ptr); 8821 if (!wdev->current_bss) 8822 ret = -ENOLINK; 8823 else 8824 ret = rdev_update_connect_params(rdev, dev, &connect, changed); 8825 wdev_unlock(dev->ieee80211_ptr); 8826 8827 return ret; 8828 } 8829 8830 static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info) 8831 { 8832 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8833 struct net_device *dev = info->user_ptr[1]; 8834 u16 reason; 8835 int ret; 8836 8837 if (!info->attrs[NL80211_ATTR_REASON_CODE]) 8838 reason = WLAN_REASON_DEAUTH_LEAVING; 8839 else 8840 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]); 8841 8842 if (reason == 0) 8843 return -EINVAL; 8844 8845 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8846 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8847 return -EOPNOTSUPP; 8848 8849 wdev_lock(dev->ieee80211_ptr); 8850 ret = cfg80211_disconnect(rdev, dev, reason, true); 8851 wdev_unlock(dev->ieee80211_ptr); 8852 return ret; 8853 } 8854 8855 static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info) 8856 { 8857 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8858 struct net *net; 8859 int err; 8860 8861 if (info->attrs[NL80211_ATTR_PID]) { 8862 u32 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]); 8863 8864 net = get_net_ns_by_pid(pid); 8865 } else if (info->attrs[NL80211_ATTR_NETNS_FD]) { 8866 u32 fd = nla_get_u32(info->attrs[NL80211_ATTR_NETNS_FD]); 8867 8868 net = get_net_ns_by_fd(fd); 8869 } else { 8870 return -EINVAL; 8871 } 8872 8873 if (IS_ERR(net)) 8874 return PTR_ERR(net); 8875 8876 err = 0; 8877 8878 /* check if anything to do */ 8879 if (!net_eq(wiphy_net(&rdev->wiphy), net)) 8880 err = cfg80211_switch_netns(rdev, net); 8881 8882 put_net(net); 8883 return err; 8884 } 8885 8886 static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info) 8887 { 8888 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8889 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev, 8890 struct cfg80211_pmksa *pmksa) = NULL; 8891 struct net_device *dev = info->user_ptr[1]; 8892 struct cfg80211_pmksa pmksa; 8893 8894 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa)); 8895 8896 if (!info->attrs[NL80211_ATTR_MAC]) 8897 return -EINVAL; 8898 8899 if (!info->attrs[NL80211_ATTR_PMKID]) 8900 return -EINVAL; 8901 8902 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]); 8903 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8904 8905 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8906 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8907 return -EOPNOTSUPP; 8908 8909 switch (info->genlhdr->cmd) { 8910 case NL80211_CMD_SET_PMKSA: 8911 rdev_ops = rdev->ops->set_pmksa; 8912 break; 8913 case NL80211_CMD_DEL_PMKSA: 8914 rdev_ops = rdev->ops->del_pmksa; 8915 break; 8916 default: 8917 WARN_ON(1); 8918 break; 8919 } 8920 8921 if (!rdev_ops) 8922 return -EOPNOTSUPP; 8923 8924 return rdev_ops(&rdev->wiphy, dev, &pmksa); 8925 } 8926 8927 static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info) 8928 { 8929 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8930 struct net_device *dev = info->user_ptr[1]; 8931 8932 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8933 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8934 return -EOPNOTSUPP; 8935 8936 if (!rdev->ops->flush_pmksa) 8937 return -EOPNOTSUPP; 8938 8939 return rdev_flush_pmksa(rdev, dev); 8940 } 8941 8942 static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info) 8943 { 8944 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8945 struct net_device *dev = info->user_ptr[1]; 8946 u8 action_code, dialog_token; 8947 u32 peer_capability = 0; 8948 u16 status_code; 8949 u8 *peer; 8950 bool initiator; 8951 8952 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) || 8953 !rdev->ops->tdls_mgmt) 8954 return -EOPNOTSUPP; 8955 8956 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] || 8957 !info->attrs[NL80211_ATTR_STATUS_CODE] || 8958 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] || 8959 !info->attrs[NL80211_ATTR_IE] || 8960 !info->attrs[NL80211_ATTR_MAC]) 8961 return -EINVAL; 8962 8963 peer = nla_data(info->attrs[NL80211_ATTR_MAC]); 8964 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]); 8965 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]); 8966 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]); 8967 initiator = nla_get_flag(info->attrs[NL80211_ATTR_TDLS_INITIATOR]); 8968 if (info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY]) 8969 peer_capability = 8970 nla_get_u32(info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY]); 8971 8972 return rdev_tdls_mgmt(rdev, dev, peer, action_code, 8973 dialog_token, status_code, peer_capability, 8974 initiator, 8975 nla_data(info->attrs[NL80211_ATTR_IE]), 8976 nla_len(info->attrs[NL80211_ATTR_IE])); 8977 } 8978 8979 static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info) 8980 { 8981 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8982 struct net_device *dev = info->user_ptr[1]; 8983 enum nl80211_tdls_operation operation; 8984 u8 *peer; 8985 8986 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) || 8987 !rdev->ops->tdls_oper) 8988 return -EOPNOTSUPP; 8989 8990 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] || 8991 !info->attrs[NL80211_ATTR_MAC]) 8992 return -EINVAL; 8993 8994 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]); 8995 peer = nla_data(info->attrs[NL80211_ATTR_MAC]); 8996 8997 return rdev_tdls_oper(rdev, dev, peer, operation); 8998 } 8999 9000 static int nl80211_remain_on_channel(struct sk_buff *skb, 9001 struct genl_info *info) 9002 { 9003 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9004 struct wireless_dev *wdev = info->user_ptr[1]; 9005 struct cfg80211_chan_def chandef; 9006 struct sk_buff *msg; 9007 void *hdr; 9008 u64 cookie; 9009 u32 duration; 9010 int err; 9011 9012 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] || 9013 !info->attrs[NL80211_ATTR_DURATION]) 9014 return -EINVAL; 9015 9016 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]); 9017 9018 if (!rdev->ops->remain_on_channel || 9019 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)) 9020 return -EOPNOTSUPP; 9021 9022 /* 9023 * We should be on that channel for at least a minimum amount of 9024 * time (10ms) but no longer than the driver supports. 9025 */ 9026 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME || 9027 duration > rdev->wiphy.max_remain_on_channel_duration) 9028 return -EINVAL; 9029 9030 err = nl80211_parse_chandef(rdev, info, &chandef); 9031 if (err) 9032 return err; 9033 9034 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 9035 if (!msg) 9036 return -ENOMEM; 9037 9038 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 9039 NL80211_CMD_REMAIN_ON_CHANNEL); 9040 if (!hdr) { 9041 err = -ENOBUFS; 9042 goto free_msg; 9043 } 9044 9045 err = rdev_remain_on_channel(rdev, wdev, chandef.chan, 9046 duration, &cookie); 9047 9048 if (err) 9049 goto free_msg; 9050 9051 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 9052 NL80211_ATTR_PAD)) 9053 goto nla_put_failure; 9054 9055 genlmsg_end(msg, hdr); 9056 9057 return genlmsg_reply(msg, info); 9058 9059 nla_put_failure: 9060 err = -ENOBUFS; 9061 free_msg: 9062 nlmsg_free(msg); 9063 return err; 9064 } 9065 9066 static int nl80211_cancel_remain_on_channel(struct sk_buff *skb, 9067 struct genl_info *info) 9068 { 9069 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9070 struct wireless_dev *wdev = info->user_ptr[1]; 9071 u64 cookie; 9072 9073 if (!info->attrs[NL80211_ATTR_COOKIE]) 9074 return -EINVAL; 9075 9076 if (!rdev->ops->cancel_remain_on_channel) 9077 return -EOPNOTSUPP; 9078 9079 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]); 9080 9081 return rdev_cancel_remain_on_channel(rdev, wdev, cookie); 9082 } 9083 9084 static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb, 9085 struct genl_info *info) 9086 { 9087 struct cfg80211_bitrate_mask mask; 9088 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9089 struct net_device *dev = info->user_ptr[1]; 9090 int err; 9091 9092 if (!rdev->ops->set_bitrate_mask) 9093 return -EOPNOTSUPP; 9094 9095 err = nl80211_parse_tx_bitrate_mask(info, &mask); 9096 if (err) 9097 return err; 9098 9099 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask); 9100 } 9101 9102 static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info) 9103 { 9104 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9105 struct wireless_dev *wdev = info->user_ptr[1]; 9106 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION; 9107 9108 if (!info->attrs[NL80211_ATTR_FRAME_MATCH]) 9109 return -EINVAL; 9110 9111 if (info->attrs[NL80211_ATTR_FRAME_TYPE]) 9112 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]); 9113 9114 switch (wdev->iftype) { 9115 case NL80211_IFTYPE_STATION: 9116 case NL80211_IFTYPE_ADHOC: 9117 case NL80211_IFTYPE_P2P_CLIENT: 9118 case NL80211_IFTYPE_AP: 9119 case NL80211_IFTYPE_AP_VLAN: 9120 case NL80211_IFTYPE_MESH_POINT: 9121 case NL80211_IFTYPE_P2P_GO: 9122 case NL80211_IFTYPE_P2P_DEVICE: 9123 break; 9124 case NL80211_IFTYPE_NAN: 9125 default: 9126 return -EOPNOTSUPP; 9127 } 9128 9129 /* not much point in registering if we can't reply */ 9130 if (!rdev->ops->mgmt_tx) 9131 return -EOPNOTSUPP; 9132 9133 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type, 9134 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]), 9135 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH])); 9136 } 9137 9138 static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info) 9139 { 9140 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9141 struct wireless_dev *wdev = info->user_ptr[1]; 9142 struct cfg80211_chan_def chandef; 9143 int err; 9144 void *hdr = NULL; 9145 u64 cookie; 9146 struct sk_buff *msg = NULL; 9147 struct cfg80211_mgmt_tx_params params = { 9148 .dont_wait_for_ack = 9149 info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK], 9150 }; 9151 9152 if (!info->attrs[NL80211_ATTR_FRAME]) 9153 return -EINVAL; 9154 9155 if (!rdev->ops->mgmt_tx) 9156 return -EOPNOTSUPP; 9157 9158 switch (wdev->iftype) { 9159 case NL80211_IFTYPE_P2P_DEVICE: 9160 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ]) 9161 return -EINVAL; 9162 case NL80211_IFTYPE_STATION: 9163 case NL80211_IFTYPE_ADHOC: 9164 case NL80211_IFTYPE_P2P_CLIENT: 9165 case NL80211_IFTYPE_AP: 9166 case NL80211_IFTYPE_AP_VLAN: 9167 case NL80211_IFTYPE_MESH_POINT: 9168 case NL80211_IFTYPE_P2P_GO: 9169 break; 9170 case NL80211_IFTYPE_NAN: 9171 default: 9172 return -EOPNOTSUPP; 9173 } 9174 9175 if (info->attrs[NL80211_ATTR_DURATION]) { 9176 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX)) 9177 return -EINVAL; 9178 params.wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]); 9179 9180 /* 9181 * We should wait on the channel for at least a minimum amount 9182 * of time (10ms) but no longer than the driver supports. 9183 */ 9184 if (params.wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME || 9185 params.wait > rdev->wiphy.max_remain_on_channel_duration) 9186 return -EINVAL; 9187 } 9188 9189 params.offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK]; 9190 9191 if (params.offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX)) 9192 return -EINVAL; 9193 9194 params.no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]); 9195 9196 /* get the channel if any has been specified, otherwise pass NULL to 9197 * the driver. The latter will use the current one 9198 */ 9199 chandef.chan = NULL; 9200 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 9201 err = nl80211_parse_chandef(rdev, info, &chandef); 9202 if (err) 9203 return err; 9204 } 9205 9206 if (!chandef.chan && params.offchan) 9207 return -EINVAL; 9208 9209 params.buf = nla_data(info->attrs[NL80211_ATTR_FRAME]); 9210 params.len = nla_len(info->attrs[NL80211_ATTR_FRAME]); 9211 9212 if (info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]) { 9213 int len = nla_len(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]); 9214 int i; 9215 9216 if (len % sizeof(u16)) 9217 return -EINVAL; 9218 9219 params.n_csa_offsets = len / sizeof(u16); 9220 params.csa_offsets = 9221 nla_data(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]); 9222 9223 /* check that all the offsets fit the frame */ 9224 for (i = 0; i < params.n_csa_offsets; i++) { 9225 if (params.csa_offsets[i] >= params.len) 9226 return -EINVAL; 9227 } 9228 } 9229 9230 if (!params.dont_wait_for_ack) { 9231 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 9232 if (!msg) 9233 return -ENOMEM; 9234 9235 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 9236 NL80211_CMD_FRAME); 9237 if (!hdr) { 9238 err = -ENOBUFS; 9239 goto free_msg; 9240 } 9241 } 9242 9243 params.chan = chandef.chan; 9244 err = cfg80211_mlme_mgmt_tx(rdev, wdev, ¶ms, &cookie); 9245 if (err) 9246 goto free_msg; 9247 9248 if (msg) { 9249 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 9250 NL80211_ATTR_PAD)) 9251 goto nla_put_failure; 9252 9253 genlmsg_end(msg, hdr); 9254 return genlmsg_reply(msg, info); 9255 } 9256 9257 return 0; 9258 9259 nla_put_failure: 9260 err = -ENOBUFS; 9261 free_msg: 9262 nlmsg_free(msg); 9263 return err; 9264 } 9265 9266 static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info) 9267 { 9268 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9269 struct wireless_dev *wdev = info->user_ptr[1]; 9270 u64 cookie; 9271 9272 if (!info->attrs[NL80211_ATTR_COOKIE]) 9273 return -EINVAL; 9274 9275 if (!rdev->ops->mgmt_tx_cancel_wait) 9276 return -EOPNOTSUPP; 9277 9278 switch (wdev->iftype) { 9279 case NL80211_IFTYPE_STATION: 9280 case NL80211_IFTYPE_ADHOC: 9281 case NL80211_IFTYPE_P2P_CLIENT: 9282 case NL80211_IFTYPE_AP: 9283 case NL80211_IFTYPE_AP_VLAN: 9284 case NL80211_IFTYPE_P2P_GO: 9285 case NL80211_IFTYPE_P2P_DEVICE: 9286 break; 9287 case NL80211_IFTYPE_NAN: 9288 default: 9289 return -EOPNOTSUPP; 9290 } 9291 9292 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]); 9293 9294 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie); 9295 } 9296 9297 static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info) 9298 { 9299 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9300 struct wireless_dev *wdev; 9301 struct net_device *dev = info->user_ptr[1]; 9302 u8 ps_state; 9303 bool state; 9304 int err; 9305 9306 if (!info->attrs[NL80211_ATTR_PS_STATE]) 9307 return -EINVAL; 9308 9309 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]); 9310 9311 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED) 9312 return -EINVAL; 9313 9314 wdev = dev->ieee80211_ptr; 9315 9316 if (!rdev->ops->set_power_mgmt) 9317 return -EOPNOTSUPP; 9318 9319 state = (ps_state == NL80211_PS_ENABLED) ? true : false; 9320 9321 if (state == wdev->ps) 9322 return 0; 9323 9324 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout); 9325 if (!err) 9326 wdev->ps = state; 9327 return err; 9328 } 9329 9330 static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info) 9331 { 9332 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9333 enum nl80211_ps_state ps_state; 9334 struct wireless_dev *wdev; 9335 struct net_device *dev = info->user_ptr[1]; 9336 struct sk_buff *msg; 9337 void *hdr; 9338 int err; 9339 9340 wdev = dev->ieee80211_ptr; 9341 9342 if (!rdev->ops->set_power_mgmt) 9343 return -EOPNOTSUPP; 9344 9345 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 9346 if (!msg) 9347 return -ENOMEM; 9348 9349 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 9350 NL80211_CMD_GET_POWER_SAVE); 9351 if (!hdr) { 9352 err = -ENOBUFS; 9353 goto free_msg; 9354 } 9355 9356 if (wdev->ps) 9357 ps_state = NL80211_PS_ENABLED; 9358 else 9359 ps_state = NL80211_PS_DISABLED; 9360 9361 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state)) 9362 goto nla_put_failure; 9363 9364 genlmsg_end(msg, hdr); 9365 return genlmsg_reply(msg, info); 9366 9367 nla_put_failure: 9368 err = -ENOBUFS; 9369 free_msg: 9370 nlmsg_free(msg); 9371 return err; 9372 } 9373 9374 static const struct nla_policy 9375 nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] = { 9376 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 }, 9377 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 }, 9378 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 }, 9379 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 }, 9380 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 }, 9381 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 }, 9382 }; 9383 9384 static int nl80211_set_cqm_txe(struct genl_info *info, 9385 u32 rate, u32 pkts, u32 intvl) 9386 { 9387 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9388 struct net_device *dev = info->user_ptr[1]; 9389 struct wireless_dev *wdev = dev->ieee80211_ptr; 9390 9391 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL) 9392 return -EINVAL; 9393 9394 if (!rdev->ops->set_cqm_txe_config) 9395 return -EOPNOTSUPP; 9396 9397 if (wdev->iftype != NL80211_IFTYPE_STATION && 9398 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT) 9399 return -EOPNOTSUPP; 9400 9401 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl); 9402 } 9403 9404 static int nl80211_set_cqm_rssi(struct genl_info *info, 9405 s32 threshold, u32 hysteresis) 9406 { 9407 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9408 struct net_device *dev = info->user_ptr[1]; 9409 struct wireless_dev *wdev = dev->ieee80211_ptr; 9410 9411 if (threshold > 0) 9412 return -EINVAL; 9413 9414 /* disabling - hysteresis should also be zero then */ 9415 if (threshold == 0) 9416 hysteresis = 0; 9417 9418 if (!rdev->ops->set_cqm_rssi_config) 9419 return -EOPNOTSUPP; 9420 9421 if (wdev->iftype != NL80211_IFTYPE_STATION && 9422 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT) 9423 return -EOPNOTSUPP; 9424 9425 return rdev_set_cqm_rssi_config(rdev, dev, threshold, hysteresis); 9426 } 9427 9428 static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info) 9429 { 9430 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1]; 9431 struct nlattr *cqm; 9432 int err; 9433 9434 cqm = info->attrs[NL80211_ATTR_CQM]; 9435 if (!cqm) 9436 return -EINVAL; 9437 9438 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm, 9439 nl80211_attr_cqm_policy); 9440 if (err) 9441 return err; 9442 9443 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] && 9444 attrs[NL80211_ATTR_CQM_RSSI_HYST]) { 9445 s32 threshold = nla_get_s32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]); 9446 u32 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]); 9447 9448 return nl80211_set_cqm_rssi(info, threshold, hysteresis); 9449 } 9450 9451 if (attrs[NL80211_ATTR_CQM_TXE_RATE] && 9452 attrs[NL80211_ATTR_CQM_TXE_PKTS] && 9453 attrs[NL80211_ATTR_CQM_TXE_INTVL]) { 9454 u32 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]); 9455 u32 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]); 9456 u32 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]); 9457 9458 return nl80211_set_cqm_txe(info, rate, pkts, intvl); 9459 } 9460 9461 return -EINVAL; 9462 } 9463 9464 static int nl80211_join_ocb(struct sk_buff *skb, struct genl_info *info) 9465 { 9466 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9467 struct net_device *dev = info->user_ptr[1]; 9468 struct ocb_setup setup = {}; 9469 int err; 9470 9471 err = nl80211_parse_chandef(rdev, info, &setup.chandef); 9472 if (err) 9473 return err; 9474 9475 return cfg80211_join_ocb(rdev, dev, &setup); 9476 } 9477 9478 static int nl80211_leave_ocb(struct sk_buff *skb, struct genl_info *info) 9479 { 9480 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9481 struct net_device *dev = info->user_ptr[1]; 9482 9483 return cfg80211_leave_ocb(rdev, dev); 9484 } 9485 9486 static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info) 9487 { 9488 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9489 struct net_device *dev = info->user_ptr[1]; 9490 struct mesh_config cfg; 9491 struct mesh_setup setup; 9492 int err; 9493 9494 /* start with default */ 9495 memcpy(&cfg, &default_mesh_config, sizeof(cfg)); 9496 memcpy(&setup, &default_mesh_setup, sizeof(setup)); 9497 9498 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) { 9499 /* and parse parameters if given */ 9500 err = nl80211_parse_mesh_config(info, &cfg, NULL); 9501 if (err) 9502 return err; 9503 } 9504 9505 if (!info->attrs[NL80211_ATTR_MESH_ID] || 9506 !nla_len(info->attrs[NL80211_ATTR_MESH_ID])) 9507 return -EINVAL; 9508 9509 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]); 9510 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]); 9511 9512 if (info->attrs[NL80211_ATTR_MCAST_RATE] && 9513 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate, 9514 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]))) 9515 return -EINVAL; 9516 9517 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) { 9518 setup.beacon_interval = 9519 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]); 9520 9521 err = cfg80211_validate_beacon_int(rdev, 9522 NL80211_IFTYPE_MESH_POINT, 9523 setup.beacon_interval); 9524 if (err) 9525 return err; 9526 } 9527 9528 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) { 9529 setup.dtim_period = 9530 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]); 9531 if (setup.dtim_period < 1 || setup.dtim_period > 100) 9532 return -EINVAL; 9533 } 9534 9535 if (info->attrs[NL80211_ATTR_MESH_SETUP]) { 9536 /* parse additional setup parameters if given */ 9537 err = nl80211_parse_mesh_setup(info, &setup); 9538 if (err) 9539 return err; 9540 } 9541 9542 if (setup.user_mpm) 9543 cfg.auto_open_plinks = false; 9544 9545 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 9546 err = nl80211_parse_chandef(rdev, info, &setup.chandef); 9547 if (err) 9548 return err; 9549 } else { 9550 /* cfg80211_join_mesh() will sort it out */ 9551 setup.chandef.chan = NULL; 9552 } 9553 9554 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) { 9555 u8 *rates = nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 9556 int n_rates = 9557 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 9558 struct ieee80211_supported_band *sband; 9559 9560 if (!setup.chandef.chan) 9561 return -EINVAL; 9562 9563 sband = rdev->wiphy.bands[setup.chandef.chan->band]; 9564 9565 err = ieee80211_get_ratemask(sband, rates, n_rates, 9566 &setup.basic_rates); 9567 if (err) 9568 return err; 9569 } 9570 9571 if (info->attrs[NL80211_ATTR_TX_RATES]) { 9572 err = nl80211_parse_tx_bitrate_mask(info, &setup.beacon_rate); 9573 if (err) 9574 return err; 9575 9576 err = validate_beacon_tx_rate(rdev, setup.chandef.chan->band, 9577 &setup.beacon_rate); 9578 if (err) 9579 return err; 9580 } 9581 9582 return cfg80211_join_mesh(rdev, dev, &setup, &cfg); 9583 } 9584 9585 static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info) 9586 { 9587 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9588 struct net_device *dev = info->user_ptr[1]; 9589 9590 return cfg80211_leave_mesh(rdev, dev); 9591 } 9592 9593 #ifdef CONFIG_PM 9594 static int nl80211_send_wowlan_patterns(struct sk_buff *msg, 9595 struct cfg80211_registered_device *rdev) 9596 { 9597 struct cfg80211_wowlan *wowlan = rdev->wiphy.wowlan_config; 9598 struct nlattr *nl_pats, *nl_pat; 9599 int i, pat_len; 9600 9601 if (!wowlan->n_patterns) 9602 return 0; 9603 9604 nl_pats = nla_nest_start(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN); 9605 if (!nl_pats) 9606 return -ENOBUFS; 9607 9608 for (i = 0; i < wowlan->n_patterns; i++) { 9609 nl_pat = nla_nest_start(msg, i + 1); 9610 if (!nl_pat) 9611 return -ENOBUFS; 9612 pat_len = wowlan->patterns[i].pattern_len; 9613 if (nla_put(msg, NL80211_PKTPAT_MASK, DIV_ROUND_UP(pat_len, 8), 9614 wowlan->patterns[i].mask) || 9615 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len, 9616 wowlan->patterns[i].pattern) || 9617 nla_put_u32(msg, NL80211_PKTPAT_OFFSET, 9618 wowlan->patterns[i].pkt_offset)) 9619 return -ENOBUFS; 9620 nla_nest_end(msg, nl_pat); 9621 } 9622 nla_nest_end(msg, nl_pats); 9623 9624 return 0; 9625 } 9626 9627 static int nl80211_send_wowlan_tcp(struct sk_buff *msg, 9628 struct cfg80211_wowlan_tcp *tcp) 9629 { 9630 struct nlattr *nl_tcp; 9631 9632 if (!tcp) 9633 return 0; 9634 9635 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION); 9636 if (!nl_tcp) 9637 return -ENOBUFS; 9638 9639 if (nla_put_in_addr(msg, NL80211_WOWLAN_TCP_SRC_IPV4, tcp->src) || 9640 nla_put_in_addr(msg, NL80211_WOWLAN_TCP_DST_IPV4, tcp->dst) || 9641 nla_put(msg, NL80211_WOWLAN_TCP_DST_MAC, ETH_ALEN, tcp->dst_mac) || 9642 nla_put_u16(msg, NL80211_WOWLAN_TCP_SRC_PORT, tcp->src_port) || 9643 nla_put_u16(msg, NL80211_WOWLAN_TCP_DST_PORT, tcp->dst_port) || 9644 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD, 9645 tcp->payload_len, tcp->payload) || 9646 nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL, 9647 tcp->data_interval) || 9648 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD, 9649 tcp->wake_len, tcp->wake_data) || 9650 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_MASK, 9651 DIV_ROUND_UP(tcp->wake_len, 8), tcp->wake_mask)) 9652 return -ENOBUFS; 9653 9654 if (tcp->payload_seq.len && 9655 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ, 9656 sizeof(tcp->payload_seq), &tcp->payload_seq)) 9657 return -ENOBUFS; 9658 9659 if (tcp->payload_tok.len && 9660 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN, 9661 sizeof(tcp->payload_tok) + tcp->tokens_size, 9662 &tcp->payload_tok)) 9663 return -ENOBUFS; 9664 9665 nla_nest_end(msg, nl_tcp); 9666 9667 return 0; 9668 } 9669 9670 static int nl80211_send_wowlan_nd(struct sk_buff *msg, 9671 struct cfg80211_sched_scan_request *req) 9672 { 9673 struct nlattr *nd, *freqs, *matches, *match, *scan_plans, *scan_plan; 9674 int i; 9675 9676 if (!req) 9677 return 0; 9678 9679 nd = nla_nest_start(msg, NL80211_WOWLAN_TRIG_NET_DETECT); 9680 if (!nd) 9681 return -ENOBUFS; 9682 9683 if (req->n_scan_plans == 1 && 9684 nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_INTERVAL, 9685 req->scan_plans[0].interval * 1000)) 9686 return -ENOBUFS; 9687 9688 if (nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_DELAY, req->delay)) 9689 return -ENOBUFS; 9690 9691 freqs = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES); 9692 if (!freqs) 9693 return -ENOBUFS; 9694 9695 for (i = 0; i < req->n_channels; i++) { 9696 if (nla_put_u32(msg, i, req->channels[i]->center_freq)) 9697 return -ENOBUFS; 9698 } 9699 9700 nla_nest_end(msg, freqs); 9701 9702 if (req->n_match_sets) { 9703 matches = nla_nest_start(msg, NL80211_ATTR_SCHED_SCAN_MATCH); 9704 if (!matches) 9705 return -ENOBUFS; 9706 9707 for (i = 0; i < req->n_match_sets; i++) { 9708 match = nla_nest_start(msg, i); 9709 if (!match) 9710 return -ENOBUFS; 9711 9712 if (nla_put(msg, NL80211_SCHED_SCAN_MATCH_ATTR_SSID, 9713 req->match_sets[i].ssid.ssid_len, 9714 req->match_sets[i].ssid.ssid)) 9715 return -ENOBUFS; 9716 nla_nest_end(msg, match); 9717 } 9718 nla_nest_end(msg, matches); 9719 } 9720 9721 scan_plans = nla_nest_start(msg, NL80211_ATTR_SCHED_SCAN_PLANS); 9722 if (!scan_plans) 9723 return -ENOBUFS; 9724 9725 for (i = 0; i < req->n_scan_plans; i++) { 9726 scan_plan = nla_nest_start(msg, i + 1); 9727 if (!scan_plan) 9728 return -ENOBUFS; 9729 9730 if (!scan_plan || 9731 nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_INTERVAL, 9732 req->scan_plans[i].interval) || 9733 (req->scan_plans[i].iterations && 9734 nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_ITERATIONS, 9735 req->scan_plans[i].iterations))) 9736 return -ENOBUFS; 9737 nla_nest_end(msg, scan_plan); 9738 } 9739 nla_nest_end(msg, scan_plans); 9740 9741 nla_nest_end(msg, nd); 9742 9743 return 0; 9744 } 9745 9746 static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info) 9747 { 9748 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9749 struct sk_buff *msg; 9750 void *hdr; 9751 u32 size = NLMSG_DEFAULT_SIZE; 9752 9753 if (!rdev->wiphy.wowlan) 9754 return -EOPNOTSUPP; 9755 9756 if (rdev->wiphy.wowlan_config && rdev->wiphy.wowlan_config->tcp) { 9757 /* adjust size to have room for all the data */ 9758 size += rdev->wiphy.wowlan_config->tcp->tokens_size + 9759 rdev->wiphy.wowlan_config->tcp->payload_len + 9760 rdev->wiphy.wowlan_config->tcp->wake_len + 9761 rdev->wiphy.wowlan_config->tcp->wake_len / 8; 9762 } 9763 9764 msg = nlmsg_new(size, GFP_KERNEL); 9765 if (!msg) 9766 return -ENOMEM; 9767 9768 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 9769 NL80211_CMD_GET_WOWLAN); 9770 if (!hdr) 9771 goto nla_put_failure; 9772 9773 if (rdev->wiphy.wowlan_config) { 9774 struct nlattr *nl_wowlan; 9775 9776 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS); 9777 if (!nl_wowlan) 9778 goto nla_put_failure; 9779 9780 if ((rdev->wiphy.wowlan_config->any && 9781 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) || 9782 (rdev->wiphy.wowlan_config->disconnect && 9783 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) || 9784 (rdev->wiphy.wowlan_config->magic_pkt && 9785 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) || 9786 (rdev->wiphy.wowlan_config->gtk_rekey_failure && 9787 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) || 9788 (rdev->wiphy.wowlan_config->eap_identity_req && 9789 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) || 9790 (rdev->wiphy.wowlan_config->four_way_handshake && 9791 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) || 9792 (rdev->wiphy.wowlan_config->rfkill_release && 9793 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))) 9794 goto nla_put_failure; 9795 9796 if (nl80211_send_wowlan_patterns(msg, rdev)) 9797 goto nla_put_failure; 9798 9799 if (nl80211_send_wowlan_tcp(msg, 9800 rdev->wiphy.wowlan_config->tcp)) 9801 goto nla_put_failure; 9802 9803 if (nl80211_send_wowlan_nd( 9804 msg, 9805 rdev->wiphy.wowlan_config->nd_config)) 9806 goto nla_put_failure; 9807 9808 nla_nest_end(msg, nl_wowlan); 9809 } 9810 9811 genlmsg_end(msg, hdr); 9812 return genlmsg_reply(msg, info); 9813 9814 nla_put_failure: 9815 nlmsg_free(msg); 9816 return -ENOBUFS; 9817 } 9818 9819 static int nl80211_parse_wowlan_tcp(struct cfg80211_registered_device *rdev, 9820 struct nlattr *attr, 9821 struct cfg80211_wowlan *trig) 9822 { 9823 struct nlattr *tb[NUM_NL80211_WOWLAN_TCP]; 9824 struct cfg80211_wowlan_tcp *cfg; 9825 struct nl80211_wowlan_tcp_data_token *tok = NULL; 9826 struct nl80211_wowlan_tcp_data_seq *seq = NULL; 9827 u32 size; 9828 u32 data_size, wake_size, tokens_size = 0, wake_mask_size; 9829 int err, port; 9830 9831 if (!rdev->wiphy.wowlan->tcp) 9832 return -EINVAL; 9833 9834 err = nla_parse_nested(tb, MAX_NL80211_WOWLAN_TCP, attr, 9835 nl80211_wowlan_tcp_policy); 9836 if (err) 9837 return err; 9838 9839 if (!tb[NL80211_WOWLAN_TCP_SRC_IPV4] || 9840 !tb[NL80211_WOWLAN_TCP_DST_IPV4] || 9841 !tb[NL80211_WOWLAN_TCP_DST_MAC] || 9842 !tb[NL80211_WOWLAN_TCP_DST_PORT] || 9843 !tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD] || 9844 !tb[NL80211_WOWLAN_TCP_DATA_INTERVAL] || 9845 !tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] || 9846 !tb[NL80211_WOWLAN_TCP_WAKE_MASK]) 9847 return -EINVAL; 9848 9849 data_size = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]); 9850 if (data_size > rdev->wiphy.wowlan->tcp->data_payload_max) 9851 return -EINVAL; 9852 9853 if (nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) > 9854 rdev->wiphy.wowlan->tcp->data_interval_max || 9855 nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) == 0) 9856 return -EINVAL; 9857 9858 wake_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]); 9859 if (wake_size > rdev->wiphy.wowlan->tcp->wake_payload_max) 9860 return -EINVAL; 9861 9862 wake_mask_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_MASK]); 9863 if (wake_mask_size != DIV_ROUND_UP(wake_size, 8)) 9864 return -EINVAL; 9865 9866 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]) { 9867 u32 tokln = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]); 9868 9869 tok = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]); 9870 tokens_size = tokln - sizeof(*tok); 9871 9872 if (!tok->len || tokens_size % tok->len) 9873 return -EINVAL; 9874 if (!rdev->wiphy.wowlan->tcp->tok) 9875 return -EINVAL; 9876 if (tok->len > rdev->wiphy.wowlan->tcp->tok->max_len) 9877 return -EINVAL; 9878 if (tok->len < rdev->wiphy.wowlan->tcp->tok->min_len) 9879 return -EINVAL; 9880 if (tokens_size > rdev->wiphy.wowlan->tcp->tok->bufsize) 9881 return -EINVAL; 9882 if (tok->offset + tok->len > data_size) 9883 return -EINVAL; 9884 } 9885 9886 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]) { 9887 seq = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]); 9888 if (!rdev->wiphy.wowlan->tcp->seq) 9889 return -EINVAL; 9890 if (seq->len == 0 || seq->len > 4) 9891 return -EINVAL; 9892 if (seq->len + seq->offset > data_size) 9893 return -EINVAL; 9894 } 9895 9896 size = sizeof(*cfg); 9897 size += data_size; 9898 size += wake_size + wake_mask_size; 9899 size += tokens_size; 9900 9901 cfg = kzalloc(size, GFP_KERNEL); 9902 if (!cfg) 9903 return -ENOMEM; 9904 cfg->src = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_SRC_IPV4]); 9905 cfg->dst = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_DST_IPV4]); 9906 memcpy(cfg->dst_mac, nla_data(tb[NL80211_WOWLAN_TCP_DST_MAC]), 9907 ETH_ALEN); 9908 if (tb[NL80211_WOWLAN_TCP_SRC_PORT]) 9909 port = nla_get_u16(tb[NL80211_WOWLAN_TCP_SRC_PORT]); 9910 else 9911 port = 0; 9912 #ifdef CONFIG_INET 9913 /* allocate a socket and port for it and use it */ 9914 err = __sock_create(wiphy_net(&rdev->wiphy), PF_INET, SOCK_STREAM, 9915 IPPROTO_TCP, &cfg->sock, 1); 9916 if (err) { 9917 kfree(cfg); 9918 return err; 9919 } 9920 if (inet_csk_get_port(cfg->sock->sk, port)) { 9921 sock_release(cfg->sock); 9922 kfree(cfg); 9923 return -EADDRINUSE; 9924 } 9925 cfg->src_port = inet_sk(cfg->sock->sk)->inet_num; 9926 #else 9927 if (!port) { 9928 kfree(cfg); 9929 return -EINVAL; 9930 } 9931 cfg->src_port = port; 9932 #endif 9933 9934 cfg->dst_port = nla_get_u16(tb[NL80211_WOWLAN_TCP_DST_PORT]); 9935 cfg->payload_len = data_size; 9936 cfg->payload = (u8 *)cfg + sizeof(*cfg) + tokens_size; 9937 memcpy((void *)cfg->payload, 9938 nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]), 9939 data_size); 9940 if (seq) 9941 cfg->payload_seq = *seq; 9942 cfg->data_interval = nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]); 9943 cfg->wake_len = wake_size; 9944 cfg->wake_data = (u8 *)cfg + sizeof(*cfg) + tokens_size + data_size; 9945 memcpy((void *)cfg->wake_data, 9946 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]), 9947 wake_size); 9948 cfg->wake_mask = (u8 *)cfg + sizeof(*cfg) + tokens_size + 9949 data_size + wake_size; 9950 memcpy((void *)cfg->wake_mask, 9951 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_MASK]), 9952 wake_mask_size); 9953 if (tok) { 9954 cfg->tokens_size = tokens_size; 9955 memcpy(&cfg->payload_tok, tok, sizeof(*tok) + tokens_size); 9956 } 9957 9958 trig->tcp = cfg; 9959 9960 return 0; 9961 } 9962 9963 static int nl80211_parse_wowlan_nd(struct cfg80211_registered_device *rdev, 9964 const struct wiphy_wowlan_support *wowlan, 9965 struct nlattr *attr, 9966 struct cfg80211_wowlan *trig) 9967 { 9968 struct nlattr **tb; 9969 int err; 9970 9971 tb = kzalloc(NUM_NL80211_ATTR * sizeof(*tb), GFP_KERNEL); 9972 if (!tb) 9973 return -ENOMEM; 9974 9975 if (!(wowlan->flags & WIPHY_WOWLAN_NET_DETECT)) { 9976 err = -EOPNOTSUPP; 9977 goto out; 9978 } 9979 9980 err = nla_parse_nested(tb, NL80211_ATTR_MAX, attr, nl80211_policy); 9981 if (err) 9982 goto out; 9983 9984 trig->nd_config = nl80211_parse_sched_scan(&rdev->wiphy, NULL, tb); 9985 err = PTR_ERR_OR_ZERO(trig->nd_config); 9986 if (err) 9987 trig->nd_config = NULL; 9988 9989 out: 9990 kfree(tb); 9991 return err; 9992 } 9993 9994 static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info) 9995 { 9996 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9997 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG]; 9998 struct cfg80211_wowlan new_triggers = {}; 9999 struct cfg80211_wowlan *ntrig; 10000 const struct wiphy_wowlan_support *wowlan = rdev->wiphy.wowlan; 10001 int err, i; 10002 bool prev_enabled = rdev->wiphy.wowlan_config; 10003 bool regular = false; 10004 10005 if (!wowlan) 10006 return -EOPNOTSUPP; 10007 10008 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) { 10009 cfg80211_rdev_free_wowlan(rdev); 10010 rdev->wiphy.wowlan_config = NULL; 10011 goto set_wakeup; 10012 } 10013 10014 err = nla_parse_nested(tb, MAX_NL80211_WOWLAN_TRIG, 10015 info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS], 10016 nl80211_wowlan_policy); 10017 if (err) 10018 return err; 10019 10020 if (tb[NL80211_WOWLAN_TRIG_ANY]) { 10021 if (!(wowlan->flags & WIPHY_WOWLAN_ANY)) 10022 return -EINVAL; 10023 new_triggers.any = true; 10024 } 10025 10026 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) { 10027 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT)) 10028 return -EINVAL; 10029 new_triggers.disconnect = true; 10030 regular = true; 10031 } 10032 10033 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) { 10034 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT)) 10035 return -EINVAL; 10036 new_triggers.magic_pkt = true; 10037 regular = true; 10038 } 10039 10040 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED]) 10041 return -EINVAL; 10042 10043 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) { 10044 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE)) 10045 return -EINVAL; 10046 new_triggers.gtk_rekey_failure = true; 10047 regular = true; 10048 } 10049 10050 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) { 10051 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ)) 10052 return -EINVAL; 10053 new_triggers.eap_identity_req = true; 10054 regular = true; 10055 } 10056 10057 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) { 10058 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE)) 10059 return -EINVAL; 10060 new_triggers.four_way_handshake = true; 10061 regular = true; 10062 } 10063 10064 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) { 10065 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE)) 10066 return -EINVAL; 10067 new_triggers.rfkill_release = true; 10068 regular = true; 10069 } 10070 10071 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) { 10072 struct nlattr *pat; 10073 int n_patterns = 0; 10074 int rem, pat_len, mask_len, pkt_offset; 10075 struct nlattr *pat_tb[NUM_NL80211_PKTPAT]; 10076 10077 regular = true; 10078 10079 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN], 10080 rem) 10081 n_patterns++; 10082 if (n_patterns > wowlan->n_patterns) 10083 return -EINVAL; 10084 10085 new_triggers.patterns = kcalloc(n_patterns, 10086 sizeof(new_triggers.patterns[0]), 10087 GFP_KERNEL); 10088 if (!new_triggers.patterns) 10089 return -ENOMEM; 10090 10091 new_triggers.n_patterns = n_patterns; 10092 i = 0; 10093 10094 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN], 10095 rem) { 10096 u8 *mask_pat; 10097 10098 nla_parse_nested(pat_tb, MAX_NL80211_PKTPAT, pat, 10099 NULL); 10100 err = -EINVAL; 10101 if (!pat_tb[NL80211_PKTPAT_MASK] || 10102 !pat_tb[NL80211_PKTPAT_PATTERN]) 10103 goto error; 10104 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]); 10105 mask_len = DIV_ROUND_UP(pat_len, 8); 10106 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len) 10107 goto error; 10108 if (pat_len > wowlan->pattern_max_len || 10109 pat_len < wowlan->pattern_min_len) 10110 goto error; 10111 10112 if (!pat_tb[NL80211_PKTPAT_OFFSET]) 10113 pkt_offset = 0; 10114 else 10115 pkt_offset = nla_get_u32( 10116 pat_tb[NL80211_PKTPAT_OFFSET]); 10117 if (pkt_offset > wowlan->max_pkt_offset) 10118 goto error; 10119 new_triggers.patterns[i].pkt_offset = pkt_offset; 10120 10121 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL); 10122 if (!mask_pat) { 10123 err = -ENOMEM; 10124 goto error; 10125 } 10126 new_triggers.patterns[i].mask = mask_pat; 10127 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]), 10128 mask_len); 10129 mask_pat += mask_len; 10130 new_triggers.patterns[i].pattern = mask_pat; 10131 new_triggers.patterns[i].pattern_len = pat_len; 10132 memcpy(mask_pat, 10133 nla_data(pat_tb[NL80211_PKTPAT_PATTERN]), 10134 pat_len); 10135 i++; 10136 } 10137 } 10138 10139 if (tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION]) { 10140 regular = true; 10141 err = nl80211_parse_wowlan_tcp( 10142 rdev, tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION], 10143 &new_triggers); 10144 if (err) 10145 goto error; 10146 } 10147 10148 if (tb[NL80211_WOWLAN_TRIG_NET_DETECT]) { 10149 regular = true; 10150 err = nl80211_parse_wowlan_nd( 10151 rdev, wowlan, tb[NL80211_WOWLAN_TRIG_NET_DETECT], 10152 &new_triggers); 10153 if (err) 10154 goto error; 10155 } 10156 10157 /* The 'any' trigger means the device continues operating more or less 10158 * as in its normal operation mode and wakes up the host on most of the 10159 * normal interrupts (like packet RX, ...) 10160 * It therefore makes little sense to combine with the more constrained 10161 * wakeup trigger modes. 10162 */ 10163 if (new_triggers.any && regular) { 10164 err = -EINVAL; 10165 goto error; 10166 } 10167 10168 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL); 10169 if (!ntrig) { 10170 err = -ENOMEM; 10171 goto error; 10172 } 10173 cfg80211_rdev_free_wowlan(rdev); 10174 rdev->wiphy.wowlan_config = ntrig; 10175 10176 set_wakeup: 10177 if (rdev->ops->set_wakeup && 10178 prev_enabled != !!rdev->wiphy.wowlan_config) 10179 rdev_set_wakeup(rdev, rdev->wiphy.wowlan_config); 10180 10181 return 0; 10182 error: 10183 for (i = 0; i < new_triggers.n_patterns; i++) 10184 kfree(new_triggers.patterns[i].mask); 10185 kfree(new_triggers.patterns); 10186 if (new_triggers.tcp && new_triggers.tcp->sock) 10187 sock_release(new_triggers.tcp->sock); 10188 kfree(new_triggers.tcp); 10189 kfree(new_triggers.nd_config); 10190 return err; 10191 } 10192 #endif 10193 10194 static int nl80211_send_coalesce_rules(struct sk_buff *msg, 10195 struct cfg80211_registered_device *rdev) 10196 { 10197 struct nlattr *nl_pats, *nl_pat, *nl_rule, *nl_rules; 10198 int i, j, pat_len; 10199 struct cfg80211_coalesce_rules *rule; 10200 10201 if (!rdev->coalesce->n_rules) 10202 return 0; 10203 10204 nl_rules = nla_nest_start(msg, NL80211_ATTR_COALESCE_RULE); 10205 if (!nl_rules) 10206 return -ENOBUFS; 10207 10208 for (i = 0; i < rdev->coalesce->n_rules; i++) { 10209 nl_rule = nla_nest_start(msg, i + 1); 10210 if (!nl_rule) 10211 return -ENOBUFS; 10212 10213 rule = &rdev->coalesce->rules[i]; 10214 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_DELAY, 10215 rule->delay)) 10216 return -ENOBUFS; 10217 10218 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_CONDITION, 10219 rule->condition)) 10220 return -ENOBUFS; 10221 10222 nl_pats = nla_nest_start(msg, 10223 NL80211_ATTR_COALESCE_RULE_PKT_PATTERN); 10224 if (!nl_pats) 10225 return -ENOBUFS; 10226 10227 for (j = 0; j < rule->n_patterns; j++) { 10228 nl_pat = nla_nest_start(msg, j + 1); 10229 if (!nl_pat) 10230 return -ENOBUFS; 10231 pat_len = rule->patterns[j].pattern_len; 10232 if (nla_put(msg, NL80211_PKTPAT_MASK, 10233 DIV_ROUND_UP(pat_len, 8), 10234 rule->patterns[j].mask) || 10235 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len, 10236 rule->patterns[j].pattern) || 10237 nla_put_u32(msg, NL80211_PKTPAT_OFFSET, 10238 rule->patterns[j].pkt_offset)) 10239 return -ENOBUFS; 10240 nla_nest_end(msg, nl_pat); 10241 } 10242 nla_nest_end(msg, nl_pats); 10243 nla_nest_end(msg, nl_rule); 10244 } 10245 nla_nest_end(msg, nl_rules); 10246 10247 return 0; 10248 } 10249 10250 static int nl80211_get_coalesce(struct sk_buff *skb, struct genl_info *info) 10251 { 10252 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10253 struct sk_buff *msg; 10254 void *hdr; 10255 10256 if (!rdev->wiphy.coalesce) 10257 return -EOPNOTSUPP; 10258 10259 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 10260 if (!msg) 10261 return -ENOMEM; 10262 10263 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 10264 NL80211_CMD_GET_COALESCE); 10265 if (!hdr) 10266 goto nla_put_failure; 10267 10268 if (rdev->coalesce && nl80211_send_coalesce_rules(msg, rdev)) 10269 goto nla_put_failure; 10270 10271 genlmsg_end(msg, hdr); 10272 return genlmsg_reply(msg, info); 10273 10274 nla_put_failure: 10275 nlmsg_free(msg); 10276 return -ENOBUFS; 10277 } 10278 10279 void cfg80211_rdev_free_coalesce(struct cfg80211_registered_device *rdev) 10280 { 10281 struct cfg80211_coalesce *coalesce = rdev->coalesce; 10282 int i, j; 10283 struct cfg80211_coalesce_rules *rule; 10284 10285 if (!coalesce) 10286 return; 10287 10288 for (i = 0; i < coalesce->n_rules; i++) { 10289 rule = &coalesce->rules[i]; 10290 for (j = 0; j < rule->n_patterns; j++) 10291 kfree(rule->patterns[j].mask); 10292 kfree(rule->patterns); 10293 } 10294 kfree(coalesce->rules); 10295 kfree(coalesce); 10296 rdev->coalesce = NULL; 10297 } 10298 10299 static int nl80211_parse_coalesce_rule(struct cfg80211_registered_device *rdev, 10300 struct nlattr *rule, 10301 struct cfg80211_coalesce_rules *new_rule) 10302 { 10303 int err, i; 10304 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce; 10305 struct nlattr *tb[NUM_NL80211_ATTR_COALESCE_RULE], *pat; 10306 int rem, pat_len, mask_len, pkt_offset, n_patterns = 0; 10307 struct nlattr *pat_tb[NUM_NL80211_PKTPAT]; 10308 10309 err = nla_parse_nested(tb, NL80211_ATTR_COALESCE_RULE_MAX, rule, 10310 nl80211_coalesce_policy); 10311 if (err) 10312 return err; 10313 10314 if (tb[NL80211_ATTR_COALESCE_RULE_DELAY]) 10315 new_rule->delay = 10316 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_DELAY]); 10317 if (new_rule->delay > coalesce->max_delay) 10318 return -EINVAL; 10319 10320 if (tb[NL80211_ATTR_COALESCE_RULE_CONDITION]) 10321 new_rule->condition = 10322 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_CONDITION]); 10323 if (new_rule->condition != NL80211_COALESCE_CONDITION_MATCH && 10324 new_rule->condition != NL80211_COALESCE_CONDITION_NO_MATCH) 10325 return -EINVAL; 10326 10327 if (!tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN]) 10328 return -EINVAL; 10329 10330 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN], 10331 rem) 10332 n_patterns++; 10333 if (n_patterns > coalesce->n_patterns) 10334 return -EINVAL; 10335 10336 new_rule->patterns = kcalloc(n_patterns, sizeof(new_rule->patterns[0]), 10337 GFP_KERNEL); 10338 if (!new_rule->patterns) 10339 return -ENOMEM; 10340 10341 new_rule->n_patterns = n_patterns; 10342 i = 0; 10343 10344 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN], 10345 rem) { 10346 u8 *mask_pat; 10347 10348 nla_parse_nested(pat_tb, MAX_NL80211_PKTPAT, pat, NULL); 10349 if (!pat_tb[NL80211_PKTPAT_MASK] || 10350 !pat_tb[NL80211_PKTPAT_PATTERN]) 10351 return -EINVAL; 10352 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]); 10353 mask_len = DIV_ROUND_UP(pat_len, 8); 10354 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len) 10355 return -EINVAL; 10356 if (pat_len > coalesce->pattern_max_len || 10357 pat_len < coalesce->pattern_min_len) 10358 return -EINVAL; 10359 10360 if (!pat_tb[NL80211_PKTPAT_OFFSET]) 10361 pkt_offset = 0; 10362 else 10363 pkt_offset = nla_get_u32(pat_tb[NL80211_PKTPAT_OFFSET]); 10364 if (pkt_offset > coalesce->max_pkt_offset) 10365 return -EINVAL; 10366 new_rule->patterns[i].pkt_offset = pkt_offset; 10367 10368 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL); 10369 if (!mask_pat) 10370 return -ENOMEM; 10371 10372 new_rule->patterns[i].mask = mask_pat; 10373 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]), 10374 mask_len); 10375 10376 mask_pat += mask_len; 10377 new_rule->patterns[i].pattern = mask_pat; 10378 new_rule->patterns[i].pattern_len = pat_len; 10379 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_PATTERN]), 10380 pat_len); 10381 i++; 10382 } 10383 10384 return 0; 10385 } 10386 10387 static int nl80211_set_coalesce(struct sk_buff *skb, struct genl_info *info) 10388 { 10389 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10390 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce; 10391 struct cfg80211_coalesce new_coalesce = {}; 10392 struct cfg80211_coalesce *n_coalesce; 10393 int err, rem_rule, n_rules = 0, i, j; 10394 struct nlattr *rule; 10395 struct cfg80211_coalesce_rules *tmp_rule; 10396 10397 if (!rdev->wiphy.coalesce || !rdev->ops->set_coalesce) 10398 return -EOPNOTSUPP; 10399 10400 if (!info->attrs[NL80211_ATTR_COALESCE_RULE]) { 10401 cfg80211_rdev_free_coalesce(rdev); 10402 rdev_set_coalesce(rdev, NULL); 10403 return 0; 10404 } 10405 10406 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE], 10407 rem_rule) 10408 n_rules++; 10409 if (n_rules > coalesce->n_rules) 10410 return -EINVAL; 10411 10412 new_coalesce.rules = kcalloc(n_rules, sizeof(new_coalesce.rules[0]), 10413 GFP_KERNEL); 10414 if (!new_coalesce.rules) 10415 return -ENOMEM; 10416 10417 new_coalesce.n_rules = n_rules; 10418 i = 0; 10419 10420 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE], 10421 rem_rule) { 10422 err = nl80211_parse_coalesce_rule(rdev, rule, 10423 &new_coalesce.rules[i]); 10424 if (err) 10425 goto error; 10426 10427 i++; 10428 } 10429 10430 err = rdev_set_coalesce(rdev, &new_coalesce); 10431 if (err) 10432 goto error; 10433 10434 n_coalesce = kmemdup(&new_coalesce, sizeof(new_coalesce), GFP_KERNEL); 10435 if (!n_coalesce) { 10436 err = -ENOMEM; 10437 goto error; 10438 } 10439 cfg80211_rdev_free_coalesce(rdev); 10440 rdev->coalesce = n_coalesce; 10441 10442 return 0; 10443 error: 10444 for (i = 0; i < new_coalesce.n_rules; i++) { 10445 tmp_rule = &new_coalesce.rules[i]; 10446 for (j = 0; j < tmp_rule->n_patterns; j++) 10447 kfree(tmp_rule->patterns[j].mask); 10448 kfree(tmp_rule->patterns); 10449 } 10450 kfree(new_coalesce.rules); 10451 10452 return err; 10453 } 10454 10455 static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info) 10456 { 10457 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10458 struct net_device *dev = info->user_ptr[1]; 10459 struct wireless_dev *wdev = dev->ieee80211_ptr; 10460 struct nlattr *tb[NUM_NL80211_REKEY_DATA]; 10461 struct cfg80211_gtk_rekey_data rekey_data; 10462 int err; 10463 10464 if (!info->attrs[NL80211_ATTR_REKEY_DATA]) 10465 return -EINVAL; 10466 10467 err = nla_parse_nested(tb, MAX_NL80211_REKEY_DATA, 10468 info->attrs[NL80211_ATTR_REKEY_DATA], 10469 nl80211_rekey_policy); 10470 if (err) 10471 return err; 10472 10473 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN) 10474 return -ERANGE; 10475 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN) 10476 return -ERANGE; 10477 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN) 10478 return -ERANGE; 10479 10480 rekey_data.kek = nla_data(tb[NL80211_REKEY_DATA_KEK]); 10481 rekey_data.kck = nla_data(tb[NL80211_REKEY_DATA_KCK]); 10482 rekey_data.replay_ctr = nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]); 10483 10484 wdev_lock(wdev); 10485 if (!wdev->current_bss) { 10486 err = -ENOTCONN; 10487 goto out; 10488 } 10489 10490 if (!rdev->ops->set_rekey_data) { 10491 err = -EOPNOTSUPP; 10492 goto out; 10493 } 10494 10495 err = rdev_set_rekey_data(rdev, dev, &rekey_data); 10496 out: 10497 wdev_unlock(wdev); 10498 return err; 10499 } 10500 10501 static int nl80211_register_unexpected_frame(struct sk_buff *skb, 10502 struct genl_info *info) 10503 { 10504 struct net_device *dev = info->user_ptr[1]; 10505 struct wireless_dev *wdev = dev->ieee80211_ptr; 10506 10507 if (wdev->iftype != NL80211_IFTYPE_AP && 10508 wdev->iftype != NL80211_IFTYPE_P2P_GO) 10509 return -EINVAL; 10510 10511 if (wdev->ap_unexpected_nlportid) 10512 return -EBUSY; 10513 10514 wdev->ap_unexpected_nlportid = info->snd_portid; 10515 return 0; 10516 } 10517 10518 static int nl80211_probe_client(struct sk_buff *skb, 10519 struct genl_info *info) 10520 { 10521 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10522 struct net_device *dev = info->user_ptr[1]; 10523 struct wireless_dev *wdev = dev->ieee80211_ptr; 10524 struct sk_buff *msg; 10525 void *hdr; 10526 const u8 *addr; 10527 u64 cookie; 10528 int err; 10529 10530 if (wdev->iftype != NL80211_IFTYPE_AP && 10531 wdev->iftype != NL80211_IFTYPE_P2P_GO) 10532 return -EOPNOTSUPP; 10533 10534 if (!info->attrs[NL80211_ATTR_MAC]) 10535 return -EINVAL; 10536 10537 if (!rdev->ops->probe_client) 10538 return -EOPNOTSUPP; 10539 10540 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 10541 if (!msg) 10542 return -ENOMEM; 10543 10544 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 10545 NL80211_CMD_PROBE_CLIENT); 10546 if (!hdr) { 10547 err = -ENOBUFS; 10548 goto free_msg; 10549 } 10550 10551 addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 10552 10553 err = rdev_probe_client(rdev, dev, addr, &cookie); 10554 if (err) 10555 goto free_msg; 10556 10557 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 10558 NL80211_ATTR_PAD)) 10559 goto nla_put_failure; 10560 10561 genlmsg_end(msg, hdr); 10562 10563 return genlmsg_reply(msg, info); 10564 10565 nla_put_failure: 10566 err = -ENOBUFS; 10567 free_msg: 10568 nlmsg_free(msg); 10569 return err; 10570 } 10571 10572 static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info) 10573 { 10574 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10575 struct cfg80211_beacon_registration *reg, *nreg; 10576 int rv; 10577 10578 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS)) 10579 return -EOPNOTSUPP; 10580 10581 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL); 10582 if (!nreg) 10583 return -ENOMEM; 10584 10585 /* First, check if already registered. */ 10586 spin_lock_bh(&rdev->beacon_registrations_lock); 10587 list_for_each_entry(reg, &rdev->beacon_registrations, list) { 10588 if (reg->nlportid == info->snd_portid) { 10589 rv = -EALREADY; 10590 goto out_err; 10591 } 10592 } 10593 /* Add it to the list */ 10594 nreg->nlportid = info->snd_portid; 10595 list_add(&nreg->list, &rdev->beacon_registrations); 10596 10597 spin_unlock_bh(&rdev->beacon_registrations_lock); 10598 10599 return 0; 10600 out_err: 10601 spin_unlock_bh(&rdev->beacon_registrations_lock); 10602 kfree(nreg); 10603 return rv; 10604 } 10605 10606 static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info) 10607 { 10608 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10609 struct wireless_dev *wdev = info->user_ptr[1]; 10610 int err; 10611 10612 if (!rdev->ops->start_p2p_device) 10613 return -EOPNOTSUPP; 10614 10615 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE) 10616 return -EOPNOTSUPP; 10617 10618 if (wdev_running(wdev)) 10619 return 0; 10620 10621 if (rfkill_blocked(rdev->rfkill)) 10622 return -ERFKILL; 10623 10624 err = rdev_start_p2p_device(rdev, wdev); 10625 if (err) 10626 return err; 10627 10628 wdev->is_running = true; 10629 rdev->opencount++; 10630 10631 return 0; 10632 } 10633 10634 static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info) 10635 { 10636 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10637 struct wireless_dev *wdev = info->user_ptr[1]; 10638 10639 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE) 10640 return -EOPNOTSUPP; 10641 10642 if (!rdev->ops->stop_p2p_device) 10643 return -EOPNOTSUPP; 10644 10645 cfg80211_stop_p2p_device(rdev, wdev); 10646 10647 return 0; 10648 } 10649 10650 static int nl80211_start_nan(struct sk_buff *skb, struct genl_info *info) 10651 { 10652 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10653 struct wireless_dev *wdev = info->user_ptr[1]; 10654 struct cfg80211_nan_conf conf = {}; 10655 int err; 10656 10657 if (wdev->iftype != NL80211_IFTYPE_NAN) 10658 return -EOPNOTSUPP; 10659 10660 if (wdev_running(wdev)) 10661 return -EEXIST; 10662 10663 if (rfkill_blocked(rdev->rfkill)) 10664 return -ERFKILL; 10665 10666 if (!info->attrs[NL80211_ATTR_NAN_MASTER_PREF]) 10667 return -EINVAL; 10668 10669 if (!info->attrs[NL80211_ATTR_NAN_DUAL]) 10670 return -EINVAL; 10671 10672 conf.master_pref = 10673 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]); 10674 if (!conf.master_pref) 10675 return -EINVAL; 10676 10677 conf.dual = nla_get_u8(info->attrs[NL80211_ATTR_NAN_DUAL]); 10678 10679 err = rdev_start_nan(rdev, wdev, &conf); 10680 if (err) 10681 return err; 10682 10683 wdev->is_running = true; 10684 rdev->opencount++; 10685 10686 return 0; 10687 } 10688 10689 static int nl80211_stop_nan(struct sk_buff *skb, struct genl_info *info) 10690 { 10691 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10692 struct wireless_dev *wdev = info->user_ptr[1]; 10693 10694 if (wdev->iftype != NL80211_IFTYPE_NAN) 10695 return -EOPNOTSUPP; 10696 10697 cfg80211_stop_nan(rdev, wdev); 10698 10699 return 0; 10700 } 10701 10702 static int validate_nan_filter(struct nlattr *filter_attr) 10703 { 10704 struct nlattr *attr; 10705 int len = 0, n_entries = 0, rem; 10706 10707 nla_for_each_nested(attr, filter_attr, rem) { 10708 len += nla_len(attr); 10709 n_entries++; 10710 } 10711 10712 if (len >= U8_MAX) 10713 return -EINVAL; 10714 10715 return n_entries; 10716 } 10717 10718 static int handle_nan_filter(struct nlattr *attr_filter, 10719 struct cfg80211_nan_func *func, 10720 bool tx) 10721 { 10722 struct nlattr *attr; 10723 int n_entries, rem, i; 10724 struct cfg80211_nan_func_filter *filter; 10725 10726 n_entries = validate_nan_filter(attr_filter); 10727 if (n_entries < 0) 10728 return n_entries; 10729 10730 BUILD_BUG_ON(sizeof(*func->rx_filters) != sizeof(*func->tx_filters)); 10731 10732 filter = kcalloc(n_entries, sizeof(*func->rx_filters), GFP_KERNEL); 10733 if (!filter) 10734 return -ENOMEM; 10735 10736 i = 0; 10737 nla_for_each_nested(attr, attr_filter, rem) { 10738 filter[i].filter = nla_memdup(attr, GFP_KERNEL); 10739 filter[i].len = nla_len(attr); 10740 i++; 10741 } 10742 if (tx) { 10743 func->num_tx_filters = n_entries; 10744 func->tx_filters = filter; 10745 } else { 10746 func->num_rx_filters = n_entries; 10747 func->rx_filters = filter; 10748 } 10749 10750 return 0; 10751 } 10752 10753 static int nl80211_nan_add_func(struct sk_buff *skb, 10754 struct genl_info *info) 10755 { 10756 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10757 struct wireless_dev *wdev = info->user_ptr[1]; 10758 struct nlattr *tb[NUM_NL80211_NAN_FUNC_ATTR], *func_attr; 10759 struct cfg80211_nan_func *func; 10760 struct sk_buff *msg = NULL; 10761 void *hdr = NULL; 10762 int err = 0; 10763 10764 if (wdev->iftype != NL80211_IFTYPE_NAN) 10765 return -EOPNOTSUPP; 10766 10767 if (!wdev_running(wdev)) 10768 return -ENOTCONN; 10769 10770 if (!info->attrs[NL80211_ATTR_NAN_FUNC]) 10771 return -EINVAL; 10772 10773 if (wdev->owner_nlportid && 10774 wdev->owner_nlportid != info->snd_portid) 10775 return -ENOTCONN; 10776 10777 err = nla_parse_nested(tb, NL80211_NAN_FUNC_ATTR_MAX, 10778 info->attrs[NL80211_ATTR_NAN_FUNC], 10779 nl80211_nan_func_policy); 10780 if (err) 10781 return err; 10782 10783 func = kzalloc(sizeof(*func), GFP_KERNEL); 10784 if (!func) 10785 return -ENOMEM; 10786 10787 func->cookie = wdev->wiphy->cookie_counter++; 10788 10789 if (!tb[NL80211_NAN_FUNC_TYPE] || 10790 nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]) > NL80211_NAN_FUNC_MAX_TYPE) { 10791 err = -EINVAL; 10792 goto out; 10793 } 10794 10795 10796 func->type = nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]); 10797 10798 if (!tb[NL80211_NAN_FUNC_SERVICE_ID]) { 10799 err = -EINVAL; 10800 goto out; 10801 } 10802 10803 memcpy(func->service_id, nla_data(tb[NL80211_NAN_FUNC_SERVICE_ID]), 10804 sizeof(func->service_id)); 10805 10806 func->close_range = 10807 nla_get_flag(tb[NL80211_NAN_FUNC_CLOSE_RANGE]); 10808 10809 if (tb[NL80211_NAN_FUNC_SERVICE_INFO]) { 10810 func->serv_spec_info_len = 10811 nla_len(tb[NL80211_NAN_FUNC_SERVICE_INFO]); 10812 func->serv_spec_info = 10813 kmemdup(nla_data(tb[NL80211_NAN_FUNC_SERVICE_INFO]), 10814 func->serv_spec_info_len, 10815 GFP_KERNEL); 10816 if (!func->serv_spec_info) { 10817 err = -ENOMEM; 10818 goto out; 10819 } 10820 } 10821 10822 if (tb[NL80211_NAN_FUNC_TTL]) 10823 func->ttl = nla_get_u32(tb[NL80211_NAN_FUNC_TTL]); 10824 10825 switch (func->type) { 10826 case NL80211_NAN_FUNC_PUBLISH: 10827 if (!tb[NL80211_NAN_FUNC_PUBLISH_TYPE]) { 10828 err = -EINVAL; 10829 goto out; 10830 } 10831 10832 func->publish_type = 10833 nla_get_u8(tb[NL80211_NAN_FUNC_PUBLISH_TYPE]); 10834 func->publish_bcast = 10835 nla_get_flag(tb[NL80211_NAN_FUNC_PUBLISH_BCAST]); 10836 10837 if ((!(func->publish_type & NL80211_NAN_SOLICITED_PUBLISH)) && 10838 func->publish_bcast) { 10839 err = -EINVAL; 10840 goto out; 10841 } 10842 break; 10843 case NL80211_NAN_FUNC_SUBSCRIBE: 10844 func->subscribe_active = 10845 nla_get_flag(tb[NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE]); 10846 break; 10847 case NL80211_NAN_FUNC_FOLLOW_UP: 10848 if (!tb[NL80211_NAN_FUNC_FOLLOW_UP_ID] || 10849 !tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID]) { 10850 err = -EINVAL; 10851 goto out; 10852 } 10853 10854 func->followup_id = 10855 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_ID]); 10856 func->followup_reqid = 10857 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID]); 10858 memcpy(func->followup_dest.addr, 10859 nla_data(tb[NL80211_NAN_FUNC_FOLLOW_UP_DEST]), 10860 sizeof(func->followup_dest.addr)); 10861 if (func->ttl) { 10862 err = -EINVAL; 10863 goto out; 10864 } 10865 break; 10866 default: 10867 err = -EINVAL; 10868 goto out; 10869 } 10870 10871 if (tb[NL80211_NAN_FUNC_SRF]) { 10872 struct nlattr *srf_tb[NUM_NL80211_NAN_SRF_ATTR]; 10873 10874 err = nla_parse_nested(srf_tb, NL80211_NAN_SRF_ATTR_MAX, 10875 tb[NL80211_NAN_FUNC_SRF], 10876 nl80211_nan_srf_policy); 10877 if (err) 10878 goto out; 10879 10880 func->srf_include = 10881 nla_get_flag(srf_tb[NL80211_NAN_SRF_INCLUDE]); 10882 10883 if (srf_tb[NL80211_NAN_SRF_BF]) { 10884 if (srf_tb[NL80211_NAN_SRF_MAC_ADDRS] || 10885 !srf_tb[NL80211_NAN_SRF_BF_IDX]) { 10886 err = -EINVAL; 10887 goto out; 10888 } 10889 10890 func->srf_bf_len = 10891 nla_len(srf_tb[NL80211_NAN_SRF_BF]); 10892 func->srf_bf = 10893 kmemdup(nla_data(srf_tb[NL80211_NAN_SRF_BF]), 10894 func->srf_bf_len, GFP_KERNEL); 10895 if (!func->srf_bf) { 10896 err = -ENOMEM; 10897 goto out; 10898 } 10899 10900 func->srf_bf_idx = 10901 nla_get_u8(srf_tb[NL80211_NAN_SRF_BF_IDX]); 10902 } else { 10903 struct nlattr *attr, *mac_attr = 10904 srf_tb[NL80211_NAN_SRF_MAC_ADDRS]; 10905 int n_entries, rem, i = 0; 10906 10907 if (!mac_attr) { 10908 err = -EINVAL; 10909 goto out; 10910 } 10911 10912 n_entries = validate_acl_mac_addrs(mac_attr); 10913 if (n_entries <= 0) { 10914 err = -EINVAL; 10915 goto out; 10916 } 10917 10918 func->srf_num_macs = n_entries; 10919 func->srf_macs = 10920 kzalloc(sizeof(*func->srf_macs) * n_entries, 10921 GFP_KERNEL); 10922 if (!func->srf_macs) { 10923 err = -ENOMEM; 10924 goto out; 10925 } 10926 10927 nla_for_each_nested(attr, mac_attr, rem) 10928 memcpy(func->srf_macs[i++].addr, nla_data(attr), 10929 sizeof(*func->srf_macs)); 10930 } 10931 } 10932 10933 if (tb[NL80211_NAN_FUNC_TX_MATCH_FILTER]) { 10934 err = handle_nan_filter(tb[NL80211_NAN_FUNC_TX_MATCH_FILTER], 10935 func, true); 10936 if (err) 10937 goto out; 10938 } 10939 10940 if (tb[NL80211_NAN_FUNC_RX_MATCH_FILTER]) { 10941 err = handle_nan_filter(tb[NL80211_NAN_FUNC_RX_MATCH_FILTER], 10942 func, false); 10943 if (err) 10944 goto out; 10945 } 10946 10947 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 10948 if (!msg) { 10949 err = -ENOMEM; 10950 goto out; 10951 } 10952 10953 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 10954 NL80211_CMD_ADD_NAN_FUNCTION); 10955 /* This can't really happen - we just allocated 4KB */ 10956 if (WARN_ON(!hdr)) { 10957 err = -ENOMEM; 10958 goto out; 10959 } 10960 10961 err = rdev_add_nan_func(rdev, wdev, func); 10962 out: 10963 if (err < 0) { 10964 cfg80211_free_nan_func(func); 10965 nlmsg_free(msg); 10966 return err; 10967 } 10968 10969 /* propagate the instance id and cookie to userspace */ 10970 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, func->cookie, 10971 NL80211_ATTR_PAD)) 10972 goto nla_put_failure; 10973 10974 func_attr = nla_nest_start(msg, NL80211_ATTR_NAN_FUNC); 10975 if (!func_attr) 10976 goto nla_put_failure; 10977 10978 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, 10979 func->instance_id)) 10980 goto nla_put_failure; 10981 10982 nla_nest_end(msg, func_attr); 10983 10984 genlmsg_end(msg, hdr); 10985 return genlmsg_reply(msg, info); 10986 10987 nla_put_failure: 10988 nlmsg_free(msg); 10989 return -ENOBUFS; 10990 } 10991 10992 static int nl80211_nan_del_func(struct sk_buff *skb, 10993 struct genl_info *info) 10994 { 10995 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10996 struct wireless_dev *wdev = info->user_ptr[1]; 10997 u64 cookie; 10998 10999 if (wdev->iftype != NL80211_IFTYPE_NAN) 11000 return -EOPNOTSUPP; 11001 11002 if (!wdev_running(wdev)) 11003 return -ENOTCONN; 11004 11005 if (!info->attrs[NL80211_ATTR_COOKIE]) 11006 return -EINVAL; 11007 11008 if (wdev->owner_nlportid && 11009 wdev->owner_nlportid != info->snd_portid) 11010 return -ENOTCONN; 11011 11012 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]); 11013 11014 rdev_del_nan_func(rdev, wdev, cookie); 11015 11016 return 0; 11017 } 11018 11019 static int nl80211_nan_change_config(struct sk_buff *skb, 11020 struct genl_info *info) 11021 { 11022 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11023 struct wireless_dev *wdev = info->user_ptr[1]; 11024 struct cfg80211_nan_conf conf = {}; 11025 u32 changed = 0; 11026 11027 if (wdev->iftype != NL80211_IFTYPE_NAN) 11028 return -EOPNOTSUPP; 11029 11030 if (!wdev_running(wdev)) 11031 return -ENOTCONN; 11032 11033 if (info->attrs[NL80211_ATTR_NAN_MASTER_PREF]) { 11034 conf.master_pref = 11035 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]); 11036 if (conf.master_pref <= 1 || conf.master_pref == 255) 11037 return -EINVAL; 11038 11039 changed |= CFG80211_NAN_CONF_CHANGED_PREF; 11040 } 11041 11042 if (info->attrs[NL80211_ATTR_NAN_DUAL]) { 11043 conf.dual = nla_get_u8(info->attrs[NL80211_ATTR_NAN_DUAL]); 11044 changed |= CFG80211_NAN_CONF_CHANGED_DUAL; 11045 } 11046 11047 if (!changed) 11048 return -EINVAL; 11049 11050 return rdev_nan_change_conf(rdev, wdev, &conf, changed); 11051 } 11052 11053 void cfg80211_nan_match(struct wireless_dev *wdev, 11054 struct cfg80211_nan_match_params *match, gfp_t gfp) 11055 { 11056 struct wiphy *wiphy = wdev->wiphy; 11057 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 11058 struct nlattr *match_attr, *local_func_attr, *peer_func_attr; 11059 struct sk_buff *msg; 11060 void *hdr; 11061 11062 if (WARN_ON(!match->inst_id || !match->peer_inst_id || !match->addr)) 11063 return; 11064 11065 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 11066 if (!msg) 11067 return; 11068 11069 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NAN_MATCH); 11070 if (!hdr) { 11071 nlmsg_free(msg); 11072 return; 11073 } 11074 11075 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 11076 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 11077 wdev->netdev->ifindex)) || 11078 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 11079 NL80211_ATTR_PAD)) 11080 goto nla_put_failure; 11081 11082 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, match->cookie, 11083 NL80211_ATTR_PAD) || 11084 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, match->addr)) 11085 goto nla_put_failure; 11086 11087 match_attr = nla_nest_start(msg, NL80211_ATTR_NAN_MATCH); 11088 if (!match_attr) 11089 goto nla_put_failure; 11090 11091 local_func_attr = nla_nest_start(msg, NL80211_NAN_MATCH_FUNC_LOCAL); 11092 if (!local_func_attr) 11093 goto nla_put_failure; 11094 11095 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->inst_id)) 11096 goto nla_put_failure; 11097 11098 nla_nest_end(msg, local_func_attr); 11099 11100 peer_func_attr = nla_nest_start(msg, NL80211_NAN_MATCH_FUNC_PEER); 11101 if (!peer_func_attr) 11102 goto nla_put_failure; 11103 11104 if (nla_put_u8(msg, NL80211_NAN_FUNC_TYPE, match->type) || 11105 nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->peer_inst_id)) 11106 goto nla_put_failure; 11107 11108 if (match->info && match->info_len && 11109 nla_put(msg, NL80211_NAN_FUNC_SERVICE_INFO, match->info_len, 11110 match->info)) 11111 goto nla_put_failure; 11112 11113 nla_nest_end(msg, peer_func_attr); 11114 nla_nest_end(msg, match_attr); 11115 genlmsg_end(msg, hdr); 11116 11117 if (!wdev->owner_nlportid) 11118 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), 11119 msg, 0, NL80211_MCGRP_NAN, gfp); 11120 else 11121 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, 11122 wdev->owner_nlportid); 11123 11124 return; 11125 11126 nla_put_failure: 11127 nlmsg_free(msg); 11128 } 11129 EXPORT_SYMBOL(cfg80211_nan_match); 11130 11131 void cfg80211_nan_func_terminated(struct wireless_dev *wdev, 11132 u8 inst_id, 11133 enum nl80211_nan_func_term_reason reason, 11134 u64 cookie, gfp_t gfp) 11135 { 11136 struct wiphy *wiphy = wdev->wiphy; 11137 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 11138 struct sk_buff *msg; 11139 struct nlattr *func_attr; 11140 void *hdr; 11141 11142 if (WARN_ON(!inst_id)) 11143 return; 11144 11145 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 11146 if (!msg) 11147 return; 11148 11149 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_NAN_FUNCTION); 11150 if (!hdr) { 11151 nlmsg_free(msg); 11152 return; 11153 } 11154 11155 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 11156 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 11157 wdev->netdev->ifindex)) || 11158 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 11159 NL80211_ATTR_PAD)) 11160 goto nla_put_failure; 11161 11162 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 11163 NL80211_ATTR_PAD)) 11164 goto nla_put_failure; 11165 11166 func_attr = nla_nest_start(msg, NL80211_ATTR_NAN_FUNC); 11167 if (!func_attr) 11168 goto nla_put_failure; 11169 11170 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, inst_id) || 11171 nla_put_u8(msg, NL80211_NAN_FUNC_TERM_REASON, reason)) 11172 goto nla_put_failure; 11173 11174 nla_nest_end(msg, func_attr); 11175 genlmsg_end(msg, hdr); 11176 11177 if (!wdev->owner_nlportid) 11178 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), 11179 msg, 0, NL80211_MCGRP_NAN, gfp); 11180 else 11181 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, 11182 wdev->owner_nlportid); 11183 11184 return; 11185 11186 nla_put_failure: 11187 nlmsg_free(msg); 11188 } 11189 EXPORT_SYMBOL(cfg80211_nan_func_terminated); 11190 11191 static int nl80211_get_protocol_features(struct sk_buff *skb, 11192 struct genl_info *info) 11193 { 11194 void *hdr; 11195 struct sk_buff *msg; 11196 11197 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 11198 if (!msg) 11199 return -ENOMEM; 11200 11201 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 11202 NL80211_CMD_GET_PROTOCOL_FEATURES); 11203 if (!hdr) 11204 goto nla_put_failure; 11205 11206 if (nla_put_u32(msg, NL80211_ATTR_PROTOCOL_FEATURES, 11207 NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP)) 11208 goto nla_put_failure; 11209 11210 genlmsg_end(msg, hdr); 11211 return genlmsg_reply(msg, info); 11212 11213 nla_put_failure: 11214 kfree_skb(msg); 11215 return -ENOBUFS; 11216 } 11217 11218 static int nl80211_update_ft_ies(struct sk_buff *skb, struct genl_info *info) 11219 { 11220 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11221 struct cfg80211_update_ft_ies_params ft_params; 11222 struct net_device *dev = info->user_ptr[1]; 11223 11224 if (!rdev->ops->update_ft_ies) 11225 return -EOPNOTSUPP; 11226 11227 if (!info->attrs[NL80211_ATTR_MDID] || 11228 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 11229 return -EINVAL; 11230 11231 memset(&ft_params, 0, sizeof(ft_params)); 11232 ft_params.md = nla_get_u16(info->attrs[NL80211_ATTR_MDID]); 11233 ft_params.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 11234 ft_params.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 11235 11236 return rdev_update_ft_ies(rdev, dev, &ft_params); 11237 } 11238 11239 static int nl80211_crit_protocol_start(struct sk_buff *skb, 11240 struct genl_info *info) 11241 { 11242 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11243 struct wireless_dev *wdev = info->user_ptr[1]; 11244 enum nl80211_crit_proto_id proto = NL80211_CRIT_PROTO_UNSPEC; 11245 u16 duration; 11246 int ret; 11247 11248 if (!rdev->ops->crit_proto_start) 11249 return -EOPNOTSUPP; 11250 11251 if (WARN_ON(!rdev->ops->crit_proto_stop)) 11252 return -EINVAL; 11253 11254 if (rdev->crit_proto_nlportid) 11255 return -EBUSY; 11256 11257 /* determine protocol if provided */ 11258 if (info->attrs[NL80211_ATTR_CRIT_PROT_ID]) 11259 proto = nla_get_u16(info->attrs[NL80211_ATTR_CRIT_PROT_ID]); 11260 11261 if (proto >= NUM_NL80211_CRIT_PROTO) 11262 return -EINVAL; 11263 11264 /* timeout must be provided */ 11265 if (!info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]) 11266 return -EINVAL; 11267 11268 duration = 11269 nla_get_u16(info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]); 11270 11271 if (duration > NL80211_CRIT_PROTO_MAX_DURATION) 11272 return -ERANGE; 11273 11274 ret = rdev_crit_proto_start(rdev, wdev, proto, duration); 11275 if (!ret) 11276 rdev->crit_proto_nlportid = info->snd_portid; 11277 11278 return ret; 11279 } 11280 11281 static int nl80211_crit_protocol_stop(struct sk_buff *skb, 11282 struct genl_info *info) 11283 { 11284 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11285 struct wireless_dev *wdev = info->user_ptr[1]; 11286 11287 if (!rdev->ops->crit_proto_stop) 11288 return -EOPNOTSUPP; 11289 11290 if (rdev->crit_proto_nlportid) { 11291 rdev->crit_proto_nlportid = 0; 11292 rdev_crit_proto_stop(rdev, wdev); 11293 } 11294 return 0; 11295 } 11296 11297 static int nl80211_vendor_cmd(struct sk_buff *skb, struct genl_info *info) 11298 { 11299 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11300 struct wireless_dev *wdev = 11301 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs); 11302 int i, err; 11303 u32 vid, subcmd; 11304 11305 if (!rdev->wiphy.vendor_commands) 11306 return -EOPNOTSUPP; 11307 11308 if (IS_ERR(wdev)) { 11309 err = PTR_ERR(wdev); 11310 if (err != -EINVAL) 11311 return err; 11312 wdev = NULL; 11313 } else if (wdev->wiphy != &rdev->wiphy) { 11314 return -EINVAL; 11315 } 11316 11317 if (!info->attrs[NL80211_ATTR_VENDOR_ID] || 11318 !info->attrs[NL80211_ATTR_VENDOR_SUBCMD]) 11319 return -EINVAL; 11320 11321 vid = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_ID]); 11322 subcmd = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_SUBCMD]); 11323 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) { 11324 const struct wiphy_vendor_command *vcmd; 11325 void *data = NULL; 11326 int len = 0; 11327 11328 vcmd = &rdev->wiphy.vendor_commands[i]; 11329 11330 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd) 11331 continue; 11332 11333 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV | 11334 WIPHY_VENDOR_CMD_NEED_NETDEV)) { 11335 if (!wdev) 11336 return -EINVAL; 11337 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV && 11338 !wdev->netdev) 11339 return -EINVAL; 11340 11341 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) { 11342 if (!wdev_running(wdev)) 11343 return -ENETDOWN; 11344 } 11345 11346 if (!vcmd->doit) 11347 return -EOPNOTSUPP; 11348 } else { 11349 wdev = NULL; 11350 } 11351 11352 if (info->attrs[NL80211_ATTR_VENDOR_DATA]) { 11353 data = nla_data(info->attrs[NL80211_ATTR_VENDOR_DATA]); 11354 len = nla_len(info->attrs[NL80211_ATTR_VENDOR_DATA]); 11355 } 11356 11357 rdev->cur_cmd_info = info; 11358 err = rdev->wiphy.vendor_commands[i].doit(&rdev->wiphy, wdev, 11359 data, len); 11360 rdev->cur_cmd_info = NULL; 11361 return err; 11362 } 11363 11364 return -EOPNOTSUPP; 11365 } 11366 11367 static int nl80211_prepare_vendor_dump(struct sk_buff *skb, 11368 struct netlink_callback *cb, 11369 struct cfg80211_registered_device **rdev, 11370 struct wireless_dev **wdev) 11371 { 11372 struct nlattr **attrbuf = genl_family_attrbuf(&nl80211_fam); 11373 u32 vid, subcmd; 11374 unsigned int i; 11375 int vcmd_idx = -1; 11376 int err; 11377 void *data = NULL; 11378 unsigned int data_len = 0; 11379 11380 rtnl_lock(); 11381 11382 if (cb->args[0]) { 11383 /* subtract the 1 again here */ 11384 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1); 11385 struct wireless_dev *tmp; 11386 11387 if (!wiphy) { 11388 err = -ENODEV; 11389 goto out_unlock; 11390 } 11391 *rdev = wiphy_to_rdev(wiphy); 11392 *wdev = NULL; 11393 11394 if (cb->args[1]) { 11395 list_for_each_entry(tmp, &wiphy->wdev_list, list) { 11396 if (tmp->identifier == cb->args[1] - 1) { 11397 *wdev = tmp; 11398 break; 11399 } 11400 } 11401 } 11402 11403 /* keep rtnl locked in successful case */ 11404 return 0; 11405 } 11406 11407 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, 11408 attrbuf, nl80211_fam.maxattr, nl80211_policy); 11409 if (err) 11410 goto out_unlock; 11411 11412 if (!attrbuf[NL80211_ATTR_VENDOR_ID] || 11413 !attrbuf[NL80211_ATTR_VENDOR_SUBCMD]) { 11414 err = -EINVAL; 11415 goto out_unlock; 11416 } 11417 11418 *wdev = __cfg80211_wdev_from_attrs(sock_net(skb->sk), attrbuf); 11419 if (IS_ERR(*wdev)) 11420 *wdev = NULL; 11421 11422 *rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf); 11423 if (IS_ERR(*rdev)) { 11424 err = PTR_ERR(*rdev); 11425 goto out_unlock; 11426 } 11427 11428 vid = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_ID]); 11429 subcmd = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_SUBCMD]); 11430 11431 for (i = 0; i < (*rdev)->wiphy.n_vendor_commands; i++) { 11432 const struct wiphy_vendor_command *vcmd; 11433 11434 vcmd = &(*rdev)->wiphy.vendor_commands[i]; 11435 11436 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd) 11437 continue; 11438 11439 if (!vcmd->dumpit) { 11440 err = -EOPNOTSUPP; 11441 goto out_unlock; 11442 } 11443 11444 vcmd_idx = i; 11445 break; 11446 } 11447 11448 if (vcmd_idx < 0) { 11449 err = -EOPNOTSUPP; 11450 goto out_unlock; 11451 } 11452 11453 if (attrbuf[NL80211_ATTR_VENDOR_DATA]) { 11454 data = nla_data(attrbuf[NL80211_ATTR_VENDOR_DATA]); 11455 data_len = nla_len(attrbuf[NL80211_ATTR_VENDOR_DATA]); 11456 } 11457 11458 /* 0 is the first index - add 1 to parse only once */ 11459 cb->args[0] = (*rdev)->wiphy_idx + 1; 11460 /* add 1 to know if it was NULL */ 11461 cb->args[1] = *wdev ? (*wdev)->identifier + 1 : 0; 11462 cb->args[2] = vcmd_idx; 11463 cb->args[3] = (unsigned long)data; 11464 cb->args[4] = data_len; 11465 11466 /* keep rtnl locked in successful case */ 11467 return 0; 11468 out_unlock: 11469 rtnl_unlock(); 11470 return err; 11471 } 11472 11473 static int nl80211_vendor_cmd_dump(struct sk_buff *skb, 11474 struct netlink_callback *cb) 11475 { 11476 struct cfg80211_registered_device *rdev; 11477 struct wireless_dev *wdev; 11478 unsigned int vcmd_idx; 11479 const struct wiphy_vendor_command *vcmd; 11480 void *data; 11481 int data_len; 11482 int err; 11483 struct nlattr *vendor_data; 11484 11485 err = nl80211_prepare_vendor_dump(skb, cb, &rdev, &wdev); 11486 if (err) 11487 return err; 11488 11489 vcmd_idx = cb->args[2]; 11490 data = (void *)cb->args[3]; 11491 data_len = cb->args[4]; 11492 vcmd = &rdev->wiphy.vendor_commands[vcmd_idx]; 11493 11494 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV | 11495 WIPHY_VENDOR_CMD_NEED_NETDEV)) { 11496 if (!wdev) 11497 return -EINVAL; 11498 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV && 11499 !wdev->netdev) 11500 return -EINVAL; 11501 11502 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) { 11503 if (!wdev_running(wdev)) 11504 return -ENETDOWN; 11505 } 11506 } 11507 11508 while (1) { 11509 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid, 11510 cb->nlh->nlmsg_seq, NLM_F_MULTI, 11511 NL80211_CMD_VENDOR); 11512 if (!hdr) 11513 break; 11514 11515 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 11516 (wdev && nla_put_u64_64bit(skb, NL80211_ATTR_WDEV, 11517 wdev_id(wdev), 11518 NL80211_ATTR_PAD))) { 11519 genlmsg_cancel(skb, hdr); 11520 break; 11521 } 11522 11523 vendor_data = nla_nest_start(skb, NL80211_ATTR_VENDOR_DATA); 11524 if (!vendor_data) { 11525 genlmsg_cancel(skb, hdr); 11526 break; 11527 } 11528 11529 err = vcmd->dumpit(&rdev->wiphy, wdev, skb, data, data_len, 11530 (unsigned long *)&cb->args[5]); 11531 nla_nest_end(skb, vendor_data); 11532 11533 if (err == -ENOBUFS || err == -ENOENT) { 11534 genlmsg_cancel(skb, hdr); 11535 break; 11536 } else if (err) { 11537 genlmsg_cancel(skb, hdr); 11538 goto out; 11539 } 11540 11541 genlmsg_end(skb, hdr); 11542 } 11543 11544 err = skb->len; 11545 out: 11546 rtnl_unlock(); 11547 return err; 11548 } 11549 11550 struct sk_buff *__cfg80211_alloc_reply_skb(struct wiphy *wiphy, 11551 enum nl80211_commands cmd, 11552 enum nl80211_attrs attr, 11553 int approxlen) 11554 { 11555 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 11556 11557 if (WARN_ON(!rdev->cur_cmd_info)) 11558 return NULL; 11559 11560 return __cfg80211_alloc_vendor_skb(rdev, NULL, approxlen, 11561 rdev->cur_cmd_info->snd_portid, 11562 rdev->cur_cmd_info->snd_seq, 11563 cmd, attr, NULL, GFP_KERNEL); 11564 } 11565 EXPORT_SYMBOL(__cfg80211_alloc_reply_skb); 11566 11567 int cfg80211_vendor_cmd_reply(struct sk_buff *skb) 11568 { 11569 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0]; 11570 void *hdr = ((void **)skb->cb)[1]; 11571 struct nlattr *data = ((void **)skb->cb)[2]; 11572 11573 /* clear CB data for netlink core to own from now on */ 11574 memset(skb->cb, 0, sizeof(skb->cb)); 11575 11576 if (WARN_ON(!rdev->cur_cmd_info)) { 11577 kfree_skb(skb); 11578 return -EINVAL; 11579 } 11580 11581 nla_nest_end(skb, data); 11582 genlmsg_end(skb, hdr); 11583 return genlmsg_reply(skb, rdev->cur_cmd_info); 11584 } 11585 EXPORT_SYMBOL_GPL(cfg80211_vendor_cmd_reply); 11586 11587 static int nl80211_set_qos_map(struct sk_buff *skb, 11588 struct genl_info *info) 11589 { 11590 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11591 struct cfg80211_qos_map *qos_map = NULL; 11592 struct net_device *dev = info->user_ptr[1]; 11593 u8 *pos, len, num_des, des_len, des; 11594 int ret; 11595 11596 if (!rdev->ops->set_qos_map) 11597 return -EOPNOTSUPP; 11598 11599 if (info->attrs[NL80211_ATTR_QOS_MAP]) { 11600 pos = nla_data(info->attrs[NL80211_ATTR_QOS_MAP]); 11601 len = nla_len(info->attrs[NL80211_ATTR_QOS_MAP]); 11602 11603 if (len % 2 || len < IEEE80211_QOS_MAP_LEN_MIN || 11604 len > IEEE80211_QOS_MAP_LEN_MAX) 11605 return -EINVAL; 11606 11607 qos_map = kzalloc(sizeof(struct cfg80211_qos_map), GFP_KERNEL); 11608 if (!qos_map) 11609 return -ENOMEM; 11610 11611 num_des = (len - IEEE80211_QOS_MAP_LEN_MIN) >> 1; 11612 if (num_des) { 11613 des_len = num_des * 11614 sizeof(struct cfg80211_dscp_exception); 11615 memcpy(qos_map->dscp_exception, pos, des_len); 11616 qos_map->num_des = num_des; 11617 for (des = 0; des < num_des; des++) { 11618 if (qos_map->dscp_exception[des].up > 7) { 11619 kfree(qos_map); 11620 return -EINVAL; 11621 } 11622 } 11623 pos += des_len; 11624 } 11625 memcpy(qos_map->up, pos, IEEE80211_QOS_MAP_LEN_MIN); 11626 } 11627 11628 wdev_lock(dev->ieee80211_ptr); 11629 ret = nl80211_key_allowed(dev->ieee80211_ptr); 11630 if (!ret) 11631 ret = rdev_set_qos_map(rdev, dev, qos_map); 11632 wdev_unlock(dev->ieee80211_ptr); 11633 11634 kfree(qos_map); 11635 return ret; 11636 } 11637 11638 static int nl80211_add_tx_ts(struct sk_buff *skb, struct genl_info *info) 11639 { 11640 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11641 struct net_device *dev = info->user_ptr[1]; 11642 struct wireless_dev *wdev = dev->ieee80211_ptr; 11643 const u8 *peer; 11644 u8 tsid, up; 11645 u16 admitted_time = 0; 11646 int err; 11647 11648 if (!(rdev->wiphy.features & NL80211_FEATURE_SUPPORTS_WMM_ADMISSION)) 11649 return -EOPNOTSUPP; 11650 11651 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC] || 11652 !info->attrs[NL80211_ATTR_USER_PRIO]) 11653 return -EINVAL; 11654 11655 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]); 11656 if (tsid >= IEEE80211_NUM_TIDS) 11657 return -EINVAL; 11658 11659 up = nla_get_u8(info->attrs[NL80211_ATTR_USER_PRIO]); 11660 if (up >= IEEE80211_NUM_UPS) 11661 return -EINVAL; 11662 11663 /* WMM uses TIDs 0-7 even for TSPEC */ 11664 if (tsid >= IEEE80211_FIRST_TSPEC_TSID) { 11665 /* TODO: handle 802.11 TSPEC/admission control 11666 * need more attributes for that (e.g. BA session requirement); 11667 * change the WMM adminssion test above to allow both then 11668 */ 11669 return -EINVAL; 11670 } 11671 11672 peer = nla_data(info->attrs[NL80211_ATTR_MAC]); 11673 11674 if (info->attrs[NL80211_ATTR_ADMITTED_TIME]) { 11675 admitted_time = 11676 nla_get_u16(info->attrs[NL80211_ATTR_ADMITTED_TIME]); 11677 if (!admitted_time) 11678 return -EINVAL; 11679 } 11680 11681 wdev_lock(wdev); 11682 switch (wdev->iftype) { 11683 case NL80211_IFTYPE_STATION: 11684 case NL80211_IFTYPE_P2P_CLIENT: 11685 if (wdev->current_bss) 11686 break; 11687 err = -ENOTCONN; 11688 goto out; 11689 default: 11690 err = -EOPNOTSUPP; 11691 goto out; 11692 } 11693 11694 err = rdev_add_tx_ts(rdev, dev, tsid, peer, up, admitted_time); 11695 11696 out: 11697 wdev_unlock(wdev); 11698 return err; 11699 } 11700 11701 static int nl80211_del_tx_ts(struct sk_buff *skb, struct genl_info *info) 11702 { 11703 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11704 struct net_device *dev = info->user_ptr[1]; 11705 struct wireless_dev *wdev = dev->ieee80211_ptr; 11706 const u8 *peer; 11707 u8 tsid; 11708 int err; 11709 11710 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC]) 11711 return -EINVAL; 11712 11713 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]); 11714 peer = nla_data(info->attrs[NL80211_ATTR_MAC]); 11715 11716 wdev_lock(wdev); 11717 err = rdev_del_tx_ts(rdev, dev, tsid, peer); 11718 wdev_unlock(wdev); 11719 11720 return err; 11721 } 11722 11723 static int nl80211_tdls_channel_switch(struct sk_buff *skb, 11724 struct genl_info *info) 11725 { 11726 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11727 struct net_device *dev = info->user_ptr[1]; 11728 struct wireless_dev *wdev = dev->ieee80211_ptr; 11729 struct cfg80211_chan_def chandef = {}; 11730 const u8 *addr; 11731 u8 oper_class; 11732 int err; 11733 11734 if (!rdev->ops->tdls_channel_switch || 11735 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH)) 11736 return -EOPNOTSUPP; 11737 11738 switch (dev->ieee80211_ptr->iftype) { 11739 case NL80211_IFTYPE_STATION: 11740 case NL80211_IFTYPE_P2P_CLIENT: 11741 break; 11742 default: 11743 return -EOPNOTSUPP; 11744 } 11745 11746 if (!info->attrs[NL80211_ATTR_MAC] || 11747 !info->attrs[NL80211_ATTR_OPER_CLASS]) 11748 return -EINVAL; 11749 11750 err = nl80211_parse_chandef(rdev, info, &chandef); 11751 if (err) 11752 return err; 11753 11754 /* 11755 * Don't allow wide channels on the 2.4Ghz band, as per IEEE802.11-2012 11756 * section 10.22.6.2.1. Disallow 5/10Mhz channels as well for now, the 11757 * specification is not defined for them. 11758 */ 11759 if (chandef.chan->band == NL80211_BAND_2GHZ && 11760 chandef.width != NL80211_CHAN_WIDTH_20_NOHT && 11761 chandef.width != NL80211_CHAN_WIDTH_20) 11762 return -EINVAL; 11763 11764 /* we will be active on the TDLS link */ 11765 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef, 11766 wdev->iftype)) 11767 return -EINVAL; 11768 11769 /* don't allow switching to DFS channels */ 11770 if (cfg80211_chandef_dfs_required(wdev->wiphy, &chandef, wdev->iftype)) 11771 return -EINVAL; 11772 11773 addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 11774 oper_class = nla_get_u8(info->attrs[NL80211_ATTR_OPER_CLASS]); 11775 11776 wdev_lock(wdev); 11777 err = rdev_tdls_channel_switch(rdev, dev, addr, oper_class, &chandef); 11778 wdev_unlock(wdev); 11779 11780 return err; 11781 } 11782 11783 static int nl80211_tdls_cancel_channel_switch(struct sk_buff *skb, 11784 struct genl_info *info) 11785 { 11786 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11787 struct net_device *dev = info->user_ptr[1]; 11788 struct wireless_dev *wdev = dev->ieee80211_ptr; 11789 const u8 *addr; 11790 11791 if (!rdev->ops->tdls_channel_switch || 11792 !rdev->ops->tdls_cancel_channel_switch || 11793 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH)) 11794 return -EOPNOTSUPP; 11795 11796 switch (dev->ieee80211_ptr->iftype) { 11797 case NL80211_IFTYPE_STATION: 11798 case NL80211_IFTYPE_P2P_CLIENT: 11799 break; 11800 default: 11801 return -EOPNOTSUPP; 11802 } 11803 11804 if (!info->attrs[NL80211_ATTR_MAC]) 11805 return -EINVAL; 11806 11807 addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 11808 11809 wdev_lock(wdev); 11810 rdev_tdls_cancel_channel_switch(rdev, dev, addr); 11811 wdev_unlock(wdev); 11812 11813 return 0; 11814 } 11815 11816 static int nl80211_set_multicast_to_unicast(struct sk_buff *skb, 11817 struct genl_info *info) 11818 { 11819 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11820 struct net_device *dev = info->user_ptr[1]; 11821 struct wireless_dev *wdev = dev->ieee80211_ptr; 11822 const struct nlattr *nla; 11823 bool enabled; 11824 11825 if (netif_running(dev)) 11826 return -EBUSY; 11827 11828 if (!rdev->ops->set_multicast_to_unicast) 11829 return -EOPNOTSUPP; 11830 11831 if (wdev->iftype != NL80211_IFTYPE_AP && 11832 wdev->iftype != NL80211_IFTYPE_P2P_GO) 11833 return -EOPNOTSUPP; 11834 11835 nla = info->attrs[NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED]; 11836 enabled = nla_get_flag(nla); 11837 11838 return rdev_set_multicast_to_unicast(rdev, dev, enabled); 11839 } 11840 11841 #define NL80211_FLAG_NEED_WIPHY 0x01 11842 #define NL80211_FLAG_NEED_NETDEV 0x02 11843 #define NL80211_FLAG_NEED_RTNL 0x04 11844 #define NL80211_FLAG_CHECK_NETDEV_UP 0x08 11845 #define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\ 11846 NL80211_FLAG_CHECK_NETDEV_UP) 11847 #define NL80211_FLAG_NEED_WDEV 0x10 11848 /* If a netdev is associated, it must be UP, P2P must be started */ 11849 #define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\ 11850 NL80211_FLAG_CHECK_NETDEV_UP) 11851 #define NL80211_FLAG_CLEAR_SKB 0x20 11852 11853 static int nl80211_pre_doit(const struct genl_ops *ops, struct sk_buff *skb, 11854 struct genl_info *info) 11855 { 11856 struct cfg80211_registered_device *rdev; 11857 struct wireless_dev *wdev; 11858 struct net_device *dev; 11859 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL; 11860 11861 if (rtnl) 11862 rtnl_lock(); 11863 11864 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) { 11865 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info); 11866 if (IS_ERR(rdev)) { 11867 if (rtnl) 11868 rtnl_unlock(); 11869 return PTR_ERR(rdev); 11870 } 11871 info->user_ptr[0] = rdev; 11872 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV || 11873 ops->internal_flags & NL80211_FLAG_NEED_WDEV) { 11874 ASSERT_RTNL(); 11875 11876 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info), 11877 info->attrs); 11878 if (IS_ERR(wdev)) { 11879 if (rtnl) 11880 rtnl_unlock(); 11881 return PTR_ERR(wdev); 11882 } 11883 11884 dev = wdev->netdev; 11885 rdev = wiphy_to_rdev(wdev->wiphy); 11886 11887 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) { 11888 if (!dev) { 11889 if (rtnl) 11890 rtnl_unlock(); 11891 return -EINVAL; 11892 } 11893 11894 info->user_ptr[1] = dev; 11895 } else { 11896 info->user_ptr[1] = wdev; 11897 } 11898 11899 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP && 11900 !wdev_running(wdev)) { 11901 if (rtnl) 11902 rtnl_unlock(); 11903 return -ENETDOWN; 11904 } 11905 11906 if (dev) 11907 dev_hold(dev); 11908 11909 info->user_ptr[0] = rdev; 11910 } 11911 11912 return 0; 11913 } 11914 11915 static void nl80211_post_doit(const struct genl_ops *ops, struct sk_buff *skb, 11916 struct genl_info *info) 11917 { 11918 if (info->user_ptr[1]) { 11919 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) { 11920 struct wireless_dev *wdev = info->user_ptr[1]; 11921 11922 if (wdev->netdev) 11923 dev_put(wdev->netdev); 11924 } else { 11925 dev_put(info->user_ptr[1]); 11926 } 11927 } 11928 11929 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL) 11930 rtnl_unlock(); 11931 11932 /* If needed, clear the netlink message payload from the SKB 11933 * as it might contain key data that shouldn't stick around on 11934 * the heap after the SKB is freed. The netlink message header 11935 * is still needed for further processing, so leave it intact. 11936 */ 11937 if (ops->internal_flags & NL80211_FLAG_CLEAR_SKB) { 11938 struct nlmsghdr *nlh = nlmsg_hdr(skb); 11939 11940 memset(nlmsg_data(nlh), 0, nlmsg_len(nlh)); 11941 } 11942 } 11943 11944 static const struct genl_ops nl80211_ops[] = { 11945 { 11946 .cmd = NL80211_CMD_GET_WIPHY, 11947 .doit = nl80211_get_wiphy, 11948 .dumpit = nl80211_dump_wiphy, 11949 .done = nl80211_dump_wiphy_done, 11950 .policy = nl80211_policy, 11951 /* can be retrieved by unprivileged users */ 11952 .internal_flags = NL80211_FLAG_NEED_WIPHY | 11953 NL80211_FLAG_NEED_RTNL, 11954 }, 11955 { 11956 .cmd = NL80211_CMD_SET_WIPHY, 11957 .doit = nl80211_set_wiphy, 11958 .policy = nl80211_policy, 11959 .flags = GENL_UNS_ADMIN_PERM, 11960 .internal_flags = NL80211_FLAG_NEED_RTNL, 11961 }, 11962 { 11963 .cmd = NL80211_CMD_GET_INTERFACE, 11964 .doit = nl80211_get_interface, 11965 .dumpit = nl80211_dump_interface, 11966 .policy = nl80211_policy, 11967 /* can be retrieved by unprivileged users */ 11968 .internal_flags = NL80211_FLAG_NEED_WDEV | 11969 NL80211_FLAG_NEED_RTNL, 11970 }, 11971 { 11972 .cmd = NL80211_CMD_SET_INTERFACE, 11973 .doit = nl80211_set_interface, 11974 .policy = nl80211_policy, 11975 .flags = GENL_UNS_ADMIN_PERM, 11976 .internal_flags = NL80211_FLAG_NEED_NETDEV | 11977 NL80211_FLAG_NEED_RTNL, 11978 }, 11979 { 11980 .cmd = NL80211_CMD_NEW_INTERFACE, 11981 .doit = nl80211_new_interface, 11982 .policy = nl80211_policy, 11983 .flags = GENL_UNS_ADMIN_PERM, 11984 .internal_flags = NL80211_FLAG_NEED_WIPHY | 11985 NL80211_FLAG_NEED_RTNL, 11986 }, 11987 { 11988 .cmd = NL80211_CMD_DEL_INTERFACE, 11989 .doit = nl80211_del_interface, 11990 .policy = nl80211_policy, 11991 .flags = GENL_UNS_ADMIN_PERM, 11992 .internal_flags = NL80211_FLAG_NEED_WDEV | 11993 NL80211_FLAG_NEED_RTNL, 11994 }, 11995 { 11996 .cmd = NL80211_CMD_GET_KEY, 11997 .doit = nl80211_get_key, 11998 .policy = nl80211_policy, 11999 .flags = GENL_UNS_ADMIN_PERM, 12000 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12001 NL80211_FLAG_NEED_RTNL, 12002 }, 12003 { 12004 .cmd = NL80211_CMD_SET_KEY, 12005 .doit = nl80211_set_key, 12006 .policy = nl80211_policy, 12007 .flags = GENL_UNS_ADMIN_PERM, 12008 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12009 NL80211_FLAG_NEED_RTNL | 12010 NL80211_FLAG_CLEAR_SKB, 12011 }, 12012 { 12013 .cmd = NL80211_CMD_NEW_KEY, 12014 .doit = nl80211_new_key, 12015 .policy = nl80211_policy, 12016 .flags = GENL_UNS_ADMIN_PERM, 12017 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12018 NL80211_FLAG_NEED_RTNL | 12019 NL80211_FLAG_CLEAR_SKB, 12020 }, 12021 { 12022 .cmd = NL80211_CMD_DEL_KEY, 12023 .doit = nl80211_del_key, 12024 .policy = nl80211_policy, 12025 .flags = GENL_UNS_ADMIN_PERM, 12026 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12027 NL80211_FLAG_NEED_RTNL, 12028 }, 12029 { 12030 .cmd = NL80211_CMD_SET_BEACON, 12031 .policy = nl80211_policy, 12032 .flags = GENL_UNS_ADMIN_PERM, 12033 .doit = nl80211_set_beacon, 12034 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12035 NL80211_FLAG_NEED_RTNL, 12036 }, 12037 { 12038 .cmd = NL80211_CMD_START_AP, 12039 .policy = nl80211_policy, 12040 .flags = GENL_UNS_ADMIN_PERM, 12041 .doit = nl80211_start_ap, 12042 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12043 NL80211_FLAG_NEED_RTNL, 12044 }, 12045 { 12046 .cmd = NL80211_CMD_STOP_AP, 12047 .policy = nl80211_policy, 12048 .flags = GENL_UNS_ADMIN_PERM, 12049 .doit = nl80211_stop_ap, 12050 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12051 NL80211_FLAG_NEED_RTNL, 12052 }, 12053 { 12054 .cmd = NL80211_CMD_GET_STATION, 12055 .doit = nl80211_get_station, 12056 .dumpit = nl80211_dump_station, 12057 .policy = nl80211_policy, 12058 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12059 NL80211_FLAG_NEED_RTNL, 12060 }, 12061 { 12062 .cmd = NL80211_CMD_SET_STATION, 12063 .doit = nl80211_set_station, 12064 .policy = nl80211_policy, 12065 .flags = GENL_UNS_ADMIN_PERM, 12066 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12067 NL80211_FLAG_NEED_RTNL, 12068 }, 12069 { 12070 .cmd = NL80211_CMD_NEW_STATION, 12071 .doit = nl80211_new_station, 12072 .policy = nl80211_policy, 12073 .flags = GENL_UNS_ADMIN_PERM, 12074 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12075 NL80211_FLAG_NEED_RTNL, 12076 }, 12077 { 12078 .cmd = NL80211_CMD_DEL_STATION, 12079 .doit = nl80211_del_station, 12080 .policy = nl80211_policy, 12081 .flags = GENL_UNS_ADMIN_PERM, 12082 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12083 NL80211_FLAG_NEED_RTNL, 12084 }, 12085 { 12086 .cmd = NL80211_CMD_GET_MPATH, 12087 .doit = nl80211_get_mpath, 12088 .dumpit = nl80211_dump_mpath, 12089 .policy = nl80211_policy, 12090 .flags = GENL_UNS_ADMIN_PERM, 12091 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12092 NL80211_FLAG_NEED_RTNL, 12093 }, 12094 { 12095 .cmd = NL80211_CMD_GET_MPP, 12096 .doit = nl80211_get_mpp, 12097 .dumpit = nl80211_dump_mpp, 12098 .policy = nl80211_policy, 12099 .flags = GENL_UNS_ADMIN_PERM, 12100 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12101 NL80211_FLAG_NEED_RTNL, 12102 }, 12103 { 12104 .cmd = NL80211_CMD_SET_MPATH, 12105 .doit = nl80211_set_mpath, 12106 .policy = nl80211_policy, 12107 .flags = GENL_UNS_ADMIN_PERM, 12108 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12109 NL80211_FLAG_NEED_RTNL, 12110 }, 12111 { 12112 .cmd = NL80211_CMD_NEW_MPATH, 12113 .doit = nl80211_new_mpath, 12114 .policy = nl80211_policy, 12115 .flags = GENL_UNS_ADMIN_PERM, 12116 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12117 NL80211_FLAG_NEED_RTNL, 12118 }, 12119 { 12120 .cmd = NL80211_CMD_DEL_MPATH, 12121 .doit = nl80211_del_mpath, 12122 .policy = nl80211_policy, 12123 .flags = GENL_UNS_ADMIN_PERM, 12124 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12125 NL80211_FLAG_NEED_RTNL, 12126 }, 12127 { 12128 .cmd = NL80211_CMD_SET_BSS, 12129 .doit = nl80211_set_bss, 12130 .policy = nl80211_policy, 12131 .flags = GENL_UNS_ADMIN_PERM, 12132 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12133 NL80211_FLAG_NEED_RTNL, 12134 }, 12135 { 12136 .cmd = NL80211_CMD_GET_REG, 12137 .doit = nl80211_get_reg_do, 12138 .dumpit = nl80211_get_reg_dump, 12139 .policy = nl80211_policy, 12140 .internal_flags = NL80211_FLAG_NEED_RTNL, 12141 /* can be retrieved by unprivileged users */ 12142 }, 12143 #ifdef CONFIG_CFG80211_CRDA_SUPPORT 12144 { 12145 .cmd = NL80211_CMD_SET_REG, 12146 .doit = nl80211_set_reg, 12147 .policy = nl80211_policy, 12148 .flags = GENL_ADMIN_PERM, 12149 .internal_flags = NL80211_FLAG_NEED_RTNL, 12150 }, 12151 #endif 12152 { 12153 .cmd = NL80211_CMD_REQ_SET_REG, 12154 .doit = nl80211_req_set_reg, 12155 .policy = nl80211_policy, 12156 .flags = GENL_ADMIN_PERM, 12157 }, 12158 { 12159 .cmd = NL80211_CMD_GET_MESH_CONFIG, 12160 .doit = nl80211_get_mesh_config, 12161 .policy = nl80211_policy, 12162 /* can be retrieved by unprivileged users */ 12163 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12164 NL80211_FLAG_NEED_RTNL, 12165 }, 12166 { 12167 .cmd = NL80211_CMD_SET_MESH_CONFIG, 12168 .doit = nl80211_update_mesh_config, 12169 .policy = nl80211_policy, 12170 .flags = GENL_UNS_ADMIN_PERM, 12171 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12172 NL80211_FLAG_NEED_RTNL, 12173 }, 12174 { 12175 .cmd = NL80211_CMD_TRIGGER_SCAN, 12176 .doit = nl80211_trigger_scan, 12177 .policy = nl80211_policy, 12178 .flags = GENL_UNS_ADMIN_PERM, 12179 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12180 NL80211_FLAG_NEED_RTNL, 12181 }, 12182 { 12183 .cmd = NL80211_CMD_ABORT_SCAN, 12184 .doit = nl80211_abort_scan, 12185 .policy = nl80211_policy, 12186 .flags = GENL_UNS_ADMIN_PERM, 12187 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12188 NL80211_FLAG_NEED_RTNL, 12189 }, 12190 { 12191 .cmd = NL80211_CMD_GET_SCAN, 12192 .policy = nl80211_policy, 12193 .dumpit = nl80211_dump_scan, 12194 }, 12195 { 12196 .cmd = NL80211_CMD_START_SCHED_SCAN, 12197 .doit = nl80211_start_sched_scan, 12198 .policy = nl80211_policy, 12199 .flags = GENL_UNS_ADMIN_PERM, 12200 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12201 NL80211_FLAG_NEED_RTNL, 12202 }, 12203 { 12204 .cmd = NL80211_CMD_STOP_SCHED_SCAN, 12205 .doit = nl80211_stop_sched_scan, 12206 .policy = nl80211_policy, 12207 .flags = GENL_UNS_ADMIN_PERM, 12208 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12209 NL80211_FLAG_NEED_RTNL, 12210 }, 12211 { 12212 .cmd = NL80211_CMD_AUTHENTICATE, 12213 .doit = nl80211_authenticate, 12214 .policy = nl80211_policy, 12215 .flags = GENL_UNS_ADMIN_PERM, 12216 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12217 NL80211_FLAG_NEED_RTNL | 12218 NL80211_FLAG_CLEAR_SKB, 12219 }, 12220 { 12221 .cmd = NL80211_CMD_ASSOCIATE, 12222 .doit = nl80211_associate, 12223 .policy = nl80211_policy, 12224 .flags = GENL_UNS_ADMIN_PERM, 12225 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12226 NL80211_FLAG_NEED_RTNL, 12227 }, 12228 { 12229 .cmd = NL80211_CMD_DEAUTHENTICATE, 12230 .doit = nl80211_deauthenticate, 12231 .policy = nl80211_policy, 12232 .flags = GENL_UNS_ADMIN_PERM, 12233 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12234 NL80211_FLAG_NEED_RTNL, 12235 }, 12236 { 12237 .cmd = NL80211_CMD_DISASSOCIATE, 12238 .doit = nl80211_disassociate, 12239 .policy = nl80211_policy, 12240 .flags = GENL_UNS_ADMIN_PERM, 12241 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12242 NL80211_FLAG_NEED_RTNL, 12243 }, 12244 { 12245 .cmd = NL80211_CMD_JOIN_IBSS, 12246 .doit = nl80211_join_ibss, 12247 .policy = nl80211_policy, 12248 .flags = GENL_UNS_ADMIN_PERM, 12249 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12250 NL80211_FLAG_NEED_RTNL, 12251 }, 12252 { 12253 .cmd = NL80211_CMD_LEAVE_IBSS, 12254 .doit = nl80211_leave_ibss, 12255 .policy = nl80211_policy, 12256 .flags = GENL_UNS_ADMIN_PERM, 12257 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12258 NL80211_FLAG_NEED_RTNL, 12259 }, 12260 #ifdef CONFIG_NL80211_TESTMODE 12261 { 12262 .cmd = NL80211_CMD_TESTMODE, 12263 .doit = nl80211_testmode_do, 12264 .dumpit = nl80211_testmode_dump, 12265 .policy = nl80211_policy, 12266 .flags = GENL_UNS_ADMIN_PERM, 12267 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12268 NL80211_FLAG_NEED_RTNL, 12269 }, 12270 #endif 12271 { 12272 .cmd = NL80211_CMD_CONNECT, 12273 .doit = nl80211_connect, 12274 .policy = nl80211_policy, 12275 .flags = GENL_UNS_ADMIN_PERM, 12276 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12277 NL80211_FLAG_NEED_RTNL, 12278 }, 12279 { 12280 .cmd = NL80211_CMD_UPDATE_CONNECT_PARAMS, 12281 .doit = nl80211_update_connect_params, 12282 .policy = nl80211_policy, 12283 .flags = GENL_ADMIN_PERM, 12284 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12285 NL80211_FLAG_NEED_RTNL, 12286 }, 12287 { 12288 .cmd = NL80211_CMD_DISCONNECT, 12289 .doit = nl80211_disconnect, 12290 .policy = nl80211_policy, 12291 .flags = GENL_UNS_ADMIN_PERM, 12292 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12293 NL80211_FLAG_NEED_RTNL, 12294 }, 12295 { 12296 .cmd = NL80211_CMD_SET_WIPHY_NETNS, 12297 .doit = nl80211_wiphy_netns, 12298 .policy = nl80211_policy, 12299 .flags = GENL_UNS_ADMIN_PERM, 12300 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12301 NL80211_FLAG_NEED_RTNL, 12302 }, 12303 { 12304 .cmd = NL80211_CMD_GET_SURVEY, 12305 .policy = nl80211_policy, 12306 .dumpit = nl80211_dump_survey, 12307 }, 12308 { 12309 .cmd = NL80211_CMD_SET_PMKSA, 12310 .doit = nl80211_setdel_pmksa, 12311 .policy = nl80211_policy, 12312 .flags = GENL_UNS_ADMIN_PERM, 12313 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12314 NL80211_FLAG_NEED_RTNL, 12315 }, 12316 { 12317 .cmd = NL80211_CMD_DEL_PMKSA, 12318 .doit = nl80211_setdel_pmksa, 12319 .policy = nl80211_policy, 12320 .flags = GENL_UNS_ADMIN_PERM, 12321 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12322 NL80211_FLAG_NEED_RTNL, 12323 }, 12324 { 12325 .cmd = NL80211_CMD_FLUSH_PMKSA, 12326 .doit = nl80211_flush_pmksa, 12327 .policy = nl80211_policy, 12328 .flags = GENL_UNS_ADMIN_PERM, 12329 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12330 NL80211_FLAG_NEED_RTNL, 12331 }, 12332 { 12333 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL, 12334 .doit = nl80211_remain_on_channel, 12335 .policy = nl80211_policy, 12336 .flags = GENL_UNS_ADMIN_PERM, 12337 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12338 NL80211_FLAG_NEED_RTNL, 12339 }, 12340 { 12341 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL, 12342 .doit = nl80211_cancel_remain_on_channel, 12343 .policy = nl80211_policy, 12344 .flags = GENL_UNS_ADMIN_PERM, 12345 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12346 NL80211_FLAG_NEED_RTNL, 12347 }, 12348 { 12349 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK, 12350 .doit = nl80211_set_tx_bitrate_mask, 12351 .policy = nl80211_policy, 12352 .flags = GENL_UNS_ADMIN_PERM, 12353 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12354 NL80211_FLAG_NEED_RTNL, 12355 }, 12356 { 12357 .cmd = NL80211_CMD_REGISTER_FRAME, 12358 .doit = nl80211_register_mgmt, 12359 .policy = nl80211_policy, 12360 .flags = GENL_UNS_ADMIN_PERM, 12361 .internal_flags = NL80211_FLAG_NEED_WDEV | 12362 NL80211_FLAG_NEED_RTNL, 12363 }, 12364 { 12365 .cmd = NL80211_CMD_FRAME, 12366 .doit = nl80211_tx_mgmt, 12367 .policy = nl80211_policy, 12368 .flags = GENL_UNS_ADMIN_PERM, 12369 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12370 NL80211_FLAG_NEED_RTNL, 12371 }, 12372 { 12373 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL, 12374 .doit = nl80211_tx_mgmt_cancel_wait, 12375 .policy = nl80211_policy, 12376 .flags = GENL_UNS_ADMIN_PERM, 12377 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12378 NL80211_FLAG_NEED_RTNL, 12379 }, 12380 { 12381 .cmd = NL80211_CMD_SET_POWER_SAVE, 12382 .doit = nl80211_set_power_save, 12383 .policy = nl80211_policy, 12384 .flags = GENL_UNS_ADMIN_PERM, 12385 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12386 NL80211_FLAG_NEED_RTNL, 12387 }, 12388 { 12389 .cmd = NL80211_CMD_GET_POWER_SAVE, 12390 .doit = nl80211_get_power_save, 12391 .policy = nl80211_policy, 12392 /* can be retrieved by unprivileged users */ 12393 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12394 NL80211_FLAG_NEED_RTNL, 12395 }, 12396 { 12397 .cmd = NL80211_CMD_SET_CQM, 12398 .doit = nl80211_set_cqm, 12399 .policy = nl80211_policy, 12400 .flags = GENL_UNS_ADMIN_PERM, 12401 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12402 NL80211_FLAG_NEED_RTNL, 12403 }, 12404 { 12405 .cmd = NL80211_CMD_SET_CHANNEL, 12406 .doit = nl80211_set_channel, 12407 .policy = nl80211_policy, 12408 .flags = GENL_UNS_ADMIN_PERM, 12409 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12410 NL80211_FLAG_NEED_RTNL, 12411 }, 12412 { 12413 .cmd = NL80211_CMD_SET_WDS_PEER, 12414 .doit = nl80211_set_wds_peer, 12415 .policy = nl80211_policy, 12416 .flags = GENL_UNS_ADMIN_PERM, 12417 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12418 NL80211_FLAG_NEED_RTNL, 12419 }, 12420 { 12421 .cmd = NL80211_CMD_JOIN_MESH, 12422 .doit = nl80211_join_mesh, 12423 .policy = nl80211_policy, 12424 .flags = GENL_UNS_ADMIN_PERM, 12425 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12426 NL80211_FLAG_NEED_RTNL, 12427 }, 12428 { 12429 .cmd = NL80211_CMD_LEAVE_MESH, 12430 .doit = nl80211_leave_mesh, 12431 .policy = nl80211_policy, 12432 .flags = GENL_UNS_ADMIN_PERM, 12433 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12434 NL80211_FLAG_NEED_RTNL, 12435 }, 12436 { 12437 .cmd = NL80211_CMD_JOIN_OCB, 12438 .doit = nl80211_join_ocb, 12439 .policy = nl80211_policy, 12440 .flags = GENL_UNS_ADMIN_PERM, 12441 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12442 NL80211_FLAG_NEED_RTNL, 12443 }, 12444 { 12445 .cmd = NL80211_CMD_LEAVE_OCB, 12446 .doit = nl80211_leave_ocb, 12447 .policy = nl80211_policy, 12448 .flags = GENL_UNS_ADMIN_PERM, 12449 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12450 NL80211_FLAG_NEED_RTNL, 12451 }, 12452 #ifdef CONFIG_PM 12453 { 12454 .cmd = NL80211_CMD_GET_WOWLAN, 12455 .doit = nl80211_get_wowlan, 12456 .policy = nl80211_policy, 12457 /* can be retrieved by unprivileged users */ 12458 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12459 NL80211_FLAG_NEED_RTNL, 12460 }, 12461 { 12462 .cmd = NL80211_CMD_SET_WOWLAN, 12463 .doit = nl80211_set_wowlan, 12464 .policy = nl80211_policy, 12465 .flags = GENL_UNS_ADMIN_PERM, 12466 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12467 NL80211_FLAG_NEED_RTNL, 12468 }, 12469 #endif 12470 { 12471 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD, 12472 .doit = nl80211_set_rekey_data, 12473 .policy = nl80211_policy, 12474 .flags = GENL_UNS_ADMIN_PERM, 12475 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12476 NL80211_FLAG_NEED_RTNL | 12477 NL80211_FLAG_CLEAR_SKB, 12478 }, 12479 { 12480 .cmd = NL80211_CMD_TDLS_MGMT, 12481 .doit = nl80211_tdls_mgmt, 12482 .policy = nl80211_policy, 12483 .flags = GENL_UNS_ADMIN_PERM, 12484 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12485 NL80211_FLAG_NEED_RTNL, 12486 }, 12487 { 12488 .cmd = NL80211_CMD_TDLS_OPER, 12489 .doit = nl80211_tdls_oper, 12490 .policy = nl80211_policy, 12491 .flags = GENL_UNS_ADMIN_PERM, 12492 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12493 NL80211_FLAG_NEED_RTNL, 12494 }, 12495 { 12496 .cmd = NL80211_CMD_UNEXPECTED_FRAME, 12497 .doit = nl80211_register_unexpected_frame, 12498 .policy = nl80211_policy, 12499 .flags = GENL_UNS_ADMIN_PERM, 12500 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12501 NL80211_FLAG_NEED_RTNL, 12502 }, 12503 { 12504 .cmd = NL80211_CMD_PROBE_CLIENT, 12505 .doit = nl80211_probe_client, 12506 .policy = nl80211_policy, 12507 .flags = GENL_UNS_ADMIN_PERM, 12508 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12509 NL80211_FLAG_NEED_RTNL, 12510 }, 12511 { 12512 .cmd = NL80211_CMD_REGISTER_BEACONS, 12513 .doit = nl80211_register_beacons, 12514 .policy = nl80211_policy, 12515 .flags = GENL_UNS_ADMIN_PERM, 12516 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12517 NL80211_FLAG_NEED_RTNL, 12518 }, 12519 { 12520 .cmd = NL80211_CMD_SET_NOACK_MAP, 12521 .doit = nl80211_set_noack_map, 12522 .policy = nl80211_policy, 12523 .flags = GENL_UNS_ADMIN_PERM, 12524 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12525 NL80211_FLAG_NEED_RTNL, 12526 }, 12527 { 12528 .cmd = NL80211_CMD_START_P2P_DEVICE, 12529 .doit = nl80211_start_p2p_device, 12530 .policy = nl80211_policy, 12531 .flags = GENL_UNS_ADMIN_PERM, 12532 .internal_flags = NL80211_FLAG_NEED_WDEV | 12533 NL80211_FLAG_NEED_RTNL, 12534 }, 12535 { 12536 .cmd = NL80211_CMD_STOP_P2P_DEVICE, 12537 .doit = nl80211_stop_p2p_device, 12538 .policy = nl80211_policy, 12539 .flags = GENL_UNS_ADMIN_PERM, 12540 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12541 NL80211_FLAG_NEED_RTNL, 12542 }, 12543 { 12544 .cmd = NL80211_CMD_START_NAN, 12545 .doit = nl80211_start_nan, 12546 .policy = nl80211_policy, 12547 .flags = GENL_ADMIN_PERM, 12548 .internal_flags = NL80211_FLAG_NEED_WDEV | 12549 NL80211_FLAG_NEED_RTNL, 12550 }, 12551 { 12552 .cmd = NL80211_CMD_STOP_NAN, 12553 .doit = nl80211_stop_nan, 12554 .policy = nl80211_policy, 12555 .flags = GENL_ADMIN_PERM, 12556 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12557 NL80211_FLAG_NEED_RTNL, 12558 }, 12559 { 12560 .cmd = NL80211_CMD_ADD_NAN_FUNCTION, 12561 .doit = nl80211_nan_add_func, 12562 .policy = nl80211_policy, 12563 .flags = GENL_ADMIN_PERM, 12564 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12565 NL80211_FLAG_NEED_RTNL, 12566 }, 12567 { 12568 .cmd = NL80211_CMD_DEL_NAN_FUNCTION, 12569 .doit = nl80211_nan_del_func, 12570 .policy = nl80211_policy, 12571 .flags = GENL_ADMIN_PERM, 12572 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12573 NL80211_FLAG_NEED_RTNL, 12574 }, 12575 { 12576 .cmd = NL80211_CMD_CHANGE_NAN_CONFIG, 12577 .doit = nl80211_nan_change_config, 12578 .policy = nl80211_policy, 12579 .flags = GENL_ADMIN_PERM, 12580 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12581 NL80211_FLAG_NEED_RTNL, 12582 }, 12583 { 12584 .cmd = NL80211_CMD_SET_MCAST_RATE, 12585 .doit = nl80211_set_mcast_rate, 12586 .policy = nl80211_policy, 12587 .flags = GENL_UNS_ADMIN_PERM, 12588 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12589 NL80211_FLAG_NEED_RTNL, 12590 }, 12591 { 12592 .cmd = NL80211_CMD_SET_MAC_ACL, 12593 .doit = nl80211_set_mac_acl, 12594 .policy = nl80211_policy, 12595 .flags = GENL_UNS_ADMIN_PERM, 12596 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12597 NL80211_FLAG_NEED_RTNL, 12598 }, 12599 { 12600 .cmd = NL80211_CMD_RADAR_DETECT, 12601 .doit = nl80211_start_radar_detection, 12602 .policy = nl80211_policy, 12603 .flags = GENL_UNS_ADMIN_PERM, 12604 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12605 NL80211_FLAG_NEED_RTNL, 12606 }, 12607 { 12608 .cmd = NL80211_CMD_GET_PROTOCOL_FEATURES, 12609 .doit = nl80211_get_protocol_features, 12610 .policy = nl80211_policy, 12611 }, 12612 { 12613 .cmd = NL80211_CMD_UPDATE_FT_IES, 12614 .doit = nl80211_update_ft_ies, 12615 .policy = nl80211_policy, 12616 .flags = GENL_UNS_ADMIN_PERM, 12617 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12618 NL80211_FLAG_NEED_RTNL, 12619 }, 12620 { 12621 .cmd = NL80211_CMD_CRIT_PROTOCOL_START, 12622 .doit = nl80211_crit_protocol_start, 12623 .policy = nl80211_policy, 12624 .flags = GENL_UNS_ADMIN_PERM, 12625 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12626 NL80211_FLAG_NEED_RTNL, 12627 }, 12628 { 12629 .cmd = NL80211_CMD_CRIT_PROTOCOL_STOP, 12630 .doit = nl80211_crit_protocol_stop, 12631 .policy = nl80211_policy, 12632 .flags = GENL_UNS_ADMIN_PERM, 12633 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12634 NL80211_FLAG_NEED_RTNL, 12635 }, 12636 { 12637 .cmd = NL80211_CMD_GET_COALESCE, 12638 .doit = nl80211_get_coalesce, 12639 .policy = nl80211_policy, 12640 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12641 NL80211_FLAG_NEED_RTNL, 12642 }, 12643 { 12644 .cmd = NL80211_CMD_SET_COALESCE, 12645 .doit = nl80211_set_coalesce, 12646 .policy = nl80211_policy, 12647 .flags = GENL_UNS_ADMIN_PERM, 12648 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12649 NL80211_FLAG_NEED_RTNL, 12650 }, 12651 { 12652 .cmd = NL80211_CMD_CHANNEL_SWITCH, 12653 .doit = nl80211_channel_switch, 12654 .policy = nl80211_policy, 12655 .flags = GENL_UNS_ADMIN_PERM, 12656 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12657 NL80211_FLAG_NEED_RTNL, 12658 }, 12659 { 12660 .cmd = NL80211_CMD_VENDOR, 12661 .doit = nl80211_vendor_cmd, 12662 .dumpit = nl80211_vendor_cmd_dump, 12663 .policy = nl80211_policy, 12664 .flags = GENL_UNS_ADMIN_PERM, 12665 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12666 NL80211_FLAG_NEED_RTNL, 12667 }, 12668 { 12669 .cmd = NL80211_CMD_SET_QOS_MAP, 12670 .doit = nl80211_set_qos_map, 12671 .policy = nl80211_policy, 12672 .flags = GENL_UNS_ADMIN_PERM, 12673 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12674 NL80211_FLAG_NEED_RTNL, 12675 }, 12676 { 12677 .cmd = NL80211_CMD_ADD_TX_TS, 12678 .doit = nl80211_add_tx_ts, 12679 .policy = nl80211_policy, 12680 .flags = GENL_UNS_ADMIN_PERM, 12681 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12682 NL80211_FLAG_NEED_RTNL, 12683 }, 12684 { 12685 .cmd = NL80211_CMD_DEL_TX_TS, 12686 .doit = nl80211_del_tx_ts, 12687 .policy = nl80211_policy, 12688 .flags = GENL_UNS_ADMIN_PERM, 12689 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12690 NL80211_FLAG_NEED_RTNL, 12691 }, 12692 { 12693 .cmd = NL80211_CMD_TDLS_CHANNEL_SWITCH, 12694 .doit = nl80211_tdls_channel_switch, 12695 .policy = nl80211_policy, 12696 .flags = GENL_UNS_ADMIN_PERM, 12697 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12698 NL80211_FLAG_NEED_RTNL, 12699 }, 12700 { 12701 .cmd = NL80211_CMD_TDLS_CANCEL_CHANNEL_SWITCH, 12702 .doit = nl80211_tdls_cancel_channel_switch, 12703 .policy = nl80211_policy, 12704 .flags = GENL_UNS_ADMIN_PERM, 12705 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12706 NL80211_FLAG_NEED_RTNL, 12707 }, 12708 { 12709 .cmd = NL80211_CMD_SET_MULTICAST_TO_UNICAST, 12710 .doit = nl80211_set_multicast_to_unicast, 12711 .policy = nl80211_policy, 12712 .flags = GENL_UNS_ADMIN_PERM, 12713 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12714 NL80211_FLAG_NEED_RTNL, 12715 }, 12716 }; 12717 12718 static struct genl_family nl80211_fam __ro_after_init = { 12719 .name = NL80211_GENL_NAME, /* have users key off the name instead */ 12720 .hdrsize = 0, /* no private header */ 12721 .version = 1, /* no particular meaning now */ 12722 .maxattr = NL80211_ATTR_MAX, 12723 .netnsok = true, 12724 .pre_doit = nl80211_pre_doit, 12725 .post_doit = nl80211_post_doit, 12726 .module = THIS_MODULE, 12727 .ops = nl80211_ops, 12728 .n_ops = ARRAY_SIZE(nl80211_ops), 12729 .mcgrps = nl80211_mcgrps, 12730 .n_mcgrps = ARRAY_SIZE(nl80211_mcgrps), 12731 }; 12732 12733 /* notification functions */ 12734 12735 void nl80211_notify_wiphy(struct cfg80211_registered_device *rdev, 12736 enum nl80211_commands cmd) 12737 { 12738 struct sk_buff *msg; 12739 struct nl80211_dump_wiphy_state state = {}; 12740 12741 WARN_ON(cmd != NL80211_CMD_NEW_WIPHY && 12742 cmd != NL80211_CMD_DEL_WIPHY); 12743 12744 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12745 if (!msg) 12746 return; 12747 12748 if (nl80211_send_wiphy(rdev, cmd, msg, 0, 0, 0, &state) < 0) { 12749 nlmsg_free(msg); 12750 return; 12751 } 12752 12753 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12754 NL80211_MCGRP_CONFIG, GFP_KERNEL); 12755 } 12756 12757 void nl80211_notify_iface(struct cfg80211_registered_device *rdev, 12758 struct wireless_dev *wdev, 12759 enum nl80211_commands cmd) 12760 { 12761 struct sk_buff *msg; 12762 12763 WARN_ON(cmd != NL80211_CMD_NEW_INTERFACE && 12764 cmd != NL80211_CMD_DEL_INTERFACE); 12765 12766 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12767 if (!msg) 12768 return; 12769 12770 if (nl80211_send_iface(msg, 0, 0, 0, rdev, wdev, 12771 cmd == NL80211_CMD_DEL_INTERFACE) < 0) { 12772 nlmsg_free(msg); 12773 return; 12774 } 12775 12776 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12777 NL80211_MCGRP_CONFIG, GFP_KERNEL); 12778 } 12779 12780 static int nl80211_add_scan_req(struct sk_buff *msg, 12781 struct cfg80211_registered_device *rdev) 12782 { 12783 struct cfg80211_scan_request *req = rdev->scan_req; 12784 struct nlattr *nest; 12785 int i; 12786 12787 if (WARN_ON(!req)) 12788 return 0; 12789 12790 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS); 12791 if (!nest) 12792 goto nla_put_failure; 12793 for (i = 0; i < req->n_ssids; i++) { 12794 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid)) 12795 goto nla_put_failure; 12796 } 12797 nla_nest_end(msg, nest); 12798 12799 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES); 12800 if (!nest) 12801 goto nla_put_failure; 12802 for (i = 0; i < req->n_channels; i++) { 12803 if (nla_put_u32(msg, i, req->channels[i]->center_freq)) 12804 goto nla_put_failure; 12805 } 12806 nla_nest_end(msg, nest); 12807 12808 if (req->ie && 12809 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie)) 12810 goto nla_put_failure; 12811 12812 if (req->flags && 12813 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags)) 12814 goto nla_put_failure; 12815 12816 if (req->info.scan_start_tsf && 12817 (nla_put_u64_64bit(msg, NL80211_ATTR_SCAN_START_TIME_TSF, 12818 req->info.scan_start_tsf, NL80211_BSS_PAD) || 12819 nla_put(msg, NL80211_ATTR_SCAN_START_TIME_TSF_BSSID, ETH_ALEN, 12820 req->info.tsf_bssid))) 12821 goto nla_put_failure; 12822 12823 return 0; 12824 nla_put_failure: 12825 return -ENOBUFS; 12826 } 12827 12828 static int nl80211_send_scan_msg(struct sk_buff *msg, 12829 struct cfg80211_registered_device *rdev, 12830 struct wireless_dev *wdev, 12831 u32 portid, u32 seq, int flags, 12832 u32 cmd) 12833 { 12834 void *hdr; 12835 12836 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 12837 if (!hdr) 12838 return -1; 12839 12840 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 12841 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 12842 wdev->netdev->ifindex)) || 12843 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 12844 NL80211_ATTR_PAD)) 12845 goto nla_put_failure; 12846 12847 /* ignore errors and send incomplete event anyway */ 12848 nl80211_add_scan_req(msg, rdev); 12849 12850 genlmsg_end(msg, hdr); 12851 return 0; 12852 12853 nla_put_failure: 12854 genlmsg_cancel(msg, hdr); 12855 return -EMSGSIZE; 12856 } 12857 12858 static int 12859 nl80211_send_sched_scan_msg(struct sk_buff *msg, 12860 struct cfg80211_registered_device *rdev, 12861 struct net_device *netdev, 12862 u32 portid, u32 seq, int flags, u32 cmd) 12863 { 12864 void *hdr; 12865 12866 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 12867 if (!hdr) 12868 return -1; 12869 12870 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 12871 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex)) 12872 goto nla_put_failure; 12873 12874 genlmsg_end(msg, hdr); 12875 return 0; 12876 12877 nla_put_failure: 12878 genlmsg_cancel(msg, hdr); 12879 return -EMSGSIZE; 12880 } 12881 12882 void nl80211_send_scan_start(struct cfg80211_registered_device *rdev, 12883 struct wireless_dev *wdev) 12884 { 12885 struct sk_buff *msg; 12886 12887 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12888 if (!msg) 12889 return; 12890 12891 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0, 12892 NL80211_CMD_TRIGGER_SCAN) < 0) { 12893 nlmsg_free(msg); 12894 return; 12895 } 12896 12897 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12898 NL80211_MCGRP_SCAN, GFP_KERNEL); 12899 } 12900 12901 struct sk_buff *nl80211_build_scan_msg(struct cfg80211_registered_device *rdev, 12902 struct wireless_dev *wdev, bool aborted) 12903 { 12904 struct sk_buff *msg; 12905 12906 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12907 if (!msg) 12908 return NULL; 12909 12910 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0, 12911 aborted ? NL80211_CMD_SCAN_ABORTED : 12912 NL80211_CMD_NEW_SCAN_RESULTS) < 0) { 12913 nlmsg_free(msg); 12914 return NULL; 12915 } 12916 12917 return msg; 12918 } 12919 12920 void nl80211_send_scan_result(struct cfg80211_registered_device *rdev, 12921 struct sk_buff *msg) 12922 { 12923 if (!msg) 12924 return; 12925 12926 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12927 NL80211_MCGRP_SCAN, GFP_KERNEL); 12928 } 12929 12930 void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev, 12931 struct net_device *netdev) 12932 { 12933 struct sk_buff *msg; 12934 12935 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12936 if (!msg) 12937 return; 12938 12939 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, 12940 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) { 12941 nlmsg_free(msg); 12942 return; 12943 } 12944 12945 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12946 NL80211_MCGRP_SCAN, GFP_KERNEL); 12947 } 12948 12949 void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev, 12950 struct net_device *netdev, u32 cmd) 12951 { 12952 struct sk_buff *msg; 12953 12954 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12955 if (!msg) 12956 return; 12957 12958 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) { 12959 nlmsg_free(msg); 12960 return; 12961 } 12962 12963 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12964 NL80211_MCGRP_SCAN, GFP_KERNEL); 12965 } 12966 12967 static bool nl80211_reg_change_event_fill(struct sk_buff *msg, 12968 struct regulatory_request *request) 12969 { 12970 /* Userspace can always count this one always being set */ 12971 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator)) 12972 goto nla_put_failure; 12973 12974 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') { 12975 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE, 12976 NL80211_REGDOM_TYPE_WORLD)) 12977 goto nla_put_failure; 12978 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') { 12979 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE, 12980 NL80211_REGDOM_TYPE_CUSTOM_WORLD)) 12981 goto nla_put_failure; 12982 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') || 12983 request->intersect) { 12984 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE, 12985 NL80211_REGDOM_TYPE_INTERSECTION)) 12986 goto nla_put_failure; 12987 } else { 12988 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE, 12989 NL80211_REGDOM_TYPE_COUNTRY) || 12990 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, 12991 request->alpha2)) 12992 goto nla_put_failure; 12993 } 12994 12995 if (request->wiphy_idx != WIPHY_IDX_INVALID) { 12996 struct wiphy *wiphy = wiphy_idx_to_wiphy(request->wiphy_idx); 12997 12998 if (wiphy && 12999 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx)) 13000 goto nla_put_failure; 13001 13002 if (wiphy && 13003 wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED && 13004 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG)) 13005 goto nla_put_failure; 13006 } 13007 13008 return true; 13009 13010 nla_put_failure: 13011 return false; 13012 } 13013 13014 /* 13015 * This can happen on global regulatory changes or device specific settings 13016 * based on custom regulatory domains. 13017 */ 13018 void nl80211_common_reg_change_event(enum nl80211_commands cmd_id, 13019 struct regulatory_request *request) 13020 { 13021 struct sk_buff *msg; 13022 void *hdr; 13023 13024 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 13025 if (!msg) 13026 return; 13027 13028 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd_id); 13029 if (!hdr) { 13030 nlmsg_free(msg); 13031 return; 13032 } 13033 13034 if (nl80211_reg_change_event_fill(msg, request) == false) 13035 goto nla_put_failure; 13036 13037 genlmsg_end(msg, hdr); 13038 13039 rcu_read_lock(); 13040 genlmsg_multicast_allns(&nl80211_fam, msg, 0, 13041 NL80211_MCGRP_REGULATORY, GFP_ATOMIC); 13042 rcu_read_unlock(); 13043 13044 return; 13045 13046 nla_put_failure: 13047 genlmsg_cancel(msg, hdr); 13048 nlmsg_free(msg); 13049 } 13050 13051 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev, 13052 struct net_device *netdev, 13053 const u8 *buf, size_t len, 13054 enum nl80211_commands cmd, gfp_t gfp, 13055 int uapsd_queues) 13056 { 13057 struct sk_buff *msg; 13058 void *hdr; 13059 13060 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13061 if (!msg) 13062 return; 13063 13064 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd); 13065 if (!hdr) { 13066 nlmsg_free(msg); 13067 return; 13068 } 13069 13070 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13071 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13072 nla_put(msg, NL80211_ATTR_FRAME, len, buf)) 13073 goto nla_put_failure; 13074 13075 if (uapsd_queues >= 0) { 13076 struct nlattr *nla_wmm = 13077 nla_nest_start(msg, NL80211_ATTR_STA_WME); 13078 if (!nla_wmm) 13079 goto nla_put_failure; 13080 13081 if (nla_put_u8(msg, NL80211_STA_WME_UAPSD_QUEUES, 13082 uapsd_queues)) 13083 goto nla_put_failure; 13084 13085 nla_nest_end(msg, nla_wmm); 13086 } 13087 13088 genlmsg_end(msg, hdr); 13089 13090 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13091 NL80211_MCGRP_MLME, gfp); 13092 return; 13093 13094 nla_put_failure: 13095 genlmsg_cancel(msg, hdr); 13096 nlmsg_free(msg); 13097 } 13098 13099 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev, 13100 struct net_device *netdev, const u8 *buf, 13101 size_t len, gfp_t gfp) 13102 { 13103 nl80211_send_mlme_event(rdev, netdev, buf, len, 13104 NL80211_CMD_AUTHENTICATE, gfp, -1); 13105 } 13106 13107 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev, 13108 struct net_device *netdev, const u8 *buf, 13109 size_t len, gfp_t gfp, int uapsd_queues) 13110 { 13111 nl80211_send_mlme_event(rdev, netdev, buf, len, 13112 NL80211_CMD_ASSOCIATE, gfp, uapsd_queues); 13113 } 13114 13115 void nl80211_send_deauth(struct cfg80211_registered_device *rdev, 13116 struct net_device *netdev, const u8 *buf, 13117 size_t len, gfp_t gfp) 13118 { 13119 nl80211_send_mlme_event(rdev, netdev, buf, len, 13120 NL80211_CMD_DEAUTHENTICATE, gfp, -1); 13121 } 13122 13123 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev, 13124 struct net_device *netdev, const u8 *buf, 13125 size_t len, gfp_t gfp) 13126 { 13127 nl80211_send_mlme_event(rdev, netdev, buf, len, 13128 NL80211_CMD_DISASSOCIATE, gfp, -1); 13129 } 13130 13131 void cfg80211_rx_unprot_mlme_mgmt(struct net_device *dev, const u8 *buf, 13132 size_t len) 13133 { 13134 struct wireless_dev *wdev = dev->ieee80211_ptr; 13135 struct wiphy *wiphy = wdev->wiphy; 13136 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13137 const struct ieee80211_mgmt *mgmt = (void *)buf; 13138 u32 cmd; 13139 13140 if (WARN_ON(len < 2)) 13141 return; 13142 13143 if (ieee80211_is_deauth(mgmt->frame_control)) 13144 cmd = NL80211_CMD_UNPROT_DEAUTHENTICATE; 13145 else 13146 cmd = NL80211_CMD_UNPROT_DISASSOCIATE; 13147 13148 trace_cfg80211_rx_unprot_mlme_mgmt(dev, buf, len); 13149 nl80211_send_mlme_event(rdev, dev, buf, len, cmd, GFP_ATOMIC, -1); 13150 } 13151 EXPORT_SYMBOL(cfg80211_rx_unprot_mlme_mgmt); 13152 13153 static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev, 13154 struct net_device *netdev, int cmd, 13155 const u8 *addr, gfp_t gfp) 13156 { 13157 struct sk_buff *msg; 13158 void *hdr; 13159 13160 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13161 if (!msg) 13162 return; 13163 13164 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd); 13165 if (!hdr) { 13166 nlmsg_free(msg); 13167 return; 13168 } 13169 13170 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13171 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13172 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) || 13173 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) 13174 goto nla_put_failure; 13175 13176 genlmsg_end(msg, hdr); 13177 13178 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13179 NL80211_MCGRP_MLME, gfp); 13180 return; 13181 13182 nla_put_failure: 13183 genlmsg_cancel(msg, hdr); 13184 nlmsg_free(msg); 13185 } 13186 13187 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev, 13188 struct net_device *netdev, const u8 *addr, 13189 gfp_t gfp) 13190 { 13191 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE, 13192 addr, gfp); 13193 } 13194 13195 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev, 13196 struct net_device *netdev, const u8 *addr, 13197 gfp_t gfp) 13198 { 13199 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE, 13200 addr, gfp); 13201 } 13202 13203 void nl80211_send_connect_result(struct cfg80211_registered_device *rdev, 13204 struct net_device *netdev, const u8 *bssid, 13205 const u8 *req_ie, size_t req_ie_len, 13206 const u8 *resp_ie, size_t resp_ie_len, 13207 int status, gfp_t gfp) 13208 { 13209 struct sk_buff *msg; 13210 void *hdr; 13211 13212 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13213 if (!msg) 13214 return; 13215 13216 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT); 13217 if (!hdr) { 13218 nlmsg_free(msg); 13219 return; 13220 } 13221 13222 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13223 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13224 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) || 13225 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, 13226 status < 0 ? WLAN_STATUS_UNSPECIFIED_FAILURE : 13227 status) || 13228 (status < 0 && nla_put_flag(msg, NL80211_ATTR_TIMED_OUT)) || 13229 (req_ie && 13230 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) || 13231 (resp_ie && 13232 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie))) 13233 goto nla_put_failure; 13234 13235 genlmsg_end(msg, hdr); 13236 13237 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13238 NL80211_MCGRP_MLME, gfp); 13239 return; 13240 13241 nla_put_failure: 13242 genlmsg_cancel(msg, hdr); 13243 nlmsg_free(msg); 13244 } 13245 13246 void nl80211_send_roamed(struct cfg80211_registered_device *rdev, 13247 struct net_device *netdev, const u8 *bssid, 13248 const u8 *req_ie, size_t req_ie_len, 13249 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp) 13250 { 13251 struct sk_buff *msg; 13252 void *hdr; 13253 13254 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13255 if (!msg) 13256 return; 13257 13258 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM); 13259 if (!hdr) { 13260 nlmsg_free(msg); 13261 return; 13262 } 13263 13264 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13265 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13266 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) || 13267 (req_ie && 13268 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) || 13269 (resp_ie && 13270 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie))) 13271 goto nla_put_failure; 13272 13273 genlmsg_end(msg, hdr); 13274 13275 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13276 NL80211_MCGRP_MLME, gfp); 13277 return; 13278 13279 nla_put_failure: 13280 genlmsg_cancel(msg, hdr); 13281 nlmsg_free(msg); 13282 } 13283 13284 void nl80211_send_disconnected(struct cfg80211_registered_device *rdev, 13285 struct net_device *netdev, u16 reason, 13286 const u8 *ie, size_t ie_len, bool from_ap) 13287 { 13288 struct sk_buff *msg; 13289 void *hdr; 13290 13291 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 13292 if (!msg) 13293 return; 13294 13295 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT); 13296 if (!hdr) { 13297 nlmsg_free(msg); 13298 return; 13299 } 13300 13301 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13302 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13303 (from_ap && reason && 13304 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) || 13305 (from_ap && 13306 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) || 13307 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie))) 13308 goto nla_put_failure; 13309 13310 genlmsg_end(msg, hdr); 13311 13312 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13313 NL80211_MCGRP_MLME, GFP_KERNEL); 13314 return; 13315 13316 nla_put_failure: 13317 genlmsg_cancel(msg, hdr); 13318 nlmsg_free(msg); 13319 } 13320 13321 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev, 13322 struct net_device *netdev, const u8 *bssid, 13323 gfp_t gfp) 13324 { 13325 struct sk_buff *msg; 13326 void *hdr; 13327 13328 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13329 if (!msg) 13330 return; 13331 13332 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS); 13333 if (!hdr) { 13334 nlmsg_free(msg); 13335 return; 13336 } 13337 13338 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13339 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13340 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) 13341 goto nla_put_failure; 13342 13343 genlmsg_end(msg, hdr); 13344 13345 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13346 NL80211_MCGRP_MLME, gfp); 13347 return; 13348 13349 nla_put_failure: 13350 genlmsg_cancel(msg, hdr); 13351 nlmsg_free(msg); 13352 } 13353 13354 void cfg80211_notify_new_peer_candidate(struct net_device *dev, const u8 *addr, 13355 const u8* ie, u8 ie_len, gfp_t gfp) 13356 { 13357 struct wireless_dev *wdev = dev->ieee80211_ptr; 13358 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 13359 struct sk_buff *msg; 13360 void *hdr; 13361 13362 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_MESH_POINT)) 13363 return; 13364 13365 trace_cfg80211_notify_new_peer_candidate(dev, addr); 13366 13367 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13368 if (!msg) 13369 return; 13370 13371 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE); 13372 if (!hdr) { 13373 nlmsg_free(msg); 13374 return; 13375 } 13376 13377 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13378 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 13379 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) || 13380 (ie_len && ie && 13381 nla_put(msg, NL80211_ATTR_IE, ie_len , ie))) 13382 goto nla_put_failure; 13383 13384 genlmsg_end(msg, hdr); 13385 13386 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13387 NL80211_MCGRP_MLME, gfp); 13388 return; 13389 13390 nla_put_failure: 13391 genlmsg_cancel(msg, hdr); 13392 nlmsg_free(msg); 13393 } 13394 EXPORT_SYMBOL(cfg80211_notify_new_peer_candidate); 13395 13396 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev, 13397 struct net_device *netdev, const u8 *addr, 13398 enum nl80211_key_type key_type, int key_id, 13399 const u8 *tsc, gfp_t gfp) 13400 { 13401 struct sk_buff *msg; 13402 void *hdr; 13403 13404 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13405 if (!msg) 13406 return; 13407 13408 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE); 13409 if (!hdr) { 13410 nlmsg_free(msg); 13411 return; 13412 } 13413 13414 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13415 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13416 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) || 13417 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) || 13418 (key_id != -1 && 13419 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) || 13420 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc))) 13421 goto nla_put_failure; 13422 13423 genlmsg_end(msg, hdr); 13424 13425 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13426 NL80211_MCGRP_MLME, gfp); 13427 return; 13428 13429 nla_put_failure: 13430 genlmsg_cancel(msg, hdr); 13431 nlmsg_free(msg); 13432 } 13433 13434 void nl80211_send_beacon_hint_event(struct wiphy *wiphy, 13435 struct ieee80211_channel *channel_before, 13436 struct ieee80211_channel *channel_after) 13437 { 13438 struct sk_buff *msg; 13439 void *hdr; 13440 struct nlattr *nl_freq; 13441 13442 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC); 13443 if (!msg) 13444 return; 13445 13446 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT); 13447 if (!hdr) { 13448 nlmsg_free(msg); 13449 return; 13450 } 13451 13452 /* 13453 * Since we are applying the beacon hint to a wiphy we know its 13454 * wiphy_idx is valid 13455 */ 13456 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy))) 13457 goto nla_put_failure; 13458 13459 /* Before */ 13460 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE); 13461 if (!nl_freq) 13462 goto nla_put_failure; 13463 if (nl80211_msg_put_channel(msg, channel_before, false)) 13464 goto nla_put_failure; 13465 nla_nest_end(msg, nl_freq); 13466 13467 /* After */ 13468 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER); 13469 if (!nl_freq) 13470 goto nla_put_failure; 13471 if (nl80211_msg_put_channel(msg, channel_after, false)) 13472 goto nla_put_failure; 13473 nla_nest_end(msg, nl_freq); 13474 13475 genlmsg_end(msg, hdr); 13476 13477 rcu_read_lock(); 13478 genlmsg_multicast_allns(&nl80211_fam, msg, 0, 13479 NL80211_MCGRP_REGULATORY, GFP_ATOMIC); 13480 rcu_read_unlock(); 13481 13482 return; 13483 13484 nla_put_failure: 13485 genlmsg_cancel(msg, hdr); 13486 nlmsg_free(msg); 13487 } 13488 13489 static void nl80211_send_remain_on_chan_event( 13490 int cmd, struct cfg80211_registered_device *rdev, 13491 struct wireless_dev *wdev, u64 cookie, 13492 struct ieee80211_channel *chan, 13493 unsigned int duration, gfp_t gfp) 13494 { 13495 struct sk_buff *msg; 13496 void *hdr; 13497 13498 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13499 if (!msg) 13500 return; 13501 13502 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd); 13503 if (!hdr) { 13504 nlmsg_free(msg); 13505 return; 13506 } 13507 13508 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13509 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 13510 wdev->netdev->ifindex)) || 13511 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 13512 NL80211_ATTR_PAD) || 13513 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) || 13514 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, 13515 NL80211_CHAN_NO_HT) || 13516 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 13517 NL80211_ATTR_PAD)) 13518 goto nla_put_failure; 13519 13520 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL && 13521 nla_put_u32(msg, NL80211_ATTR_DURATION, duration)) 13522 goto nla_put_failure; 13523 13524 genlmsg_end(msg, hdr); 13525 13526 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13527 NL80211_MCGRP_MLME, gfp); 13528 return; 13529 13530 nla_put_failure: 13531 genlmsg_cancel(msg, hdr); 13532 nlmsg_free(msg); 13533 } 13534 13535 void cfg80211_ready_on_channel(struct wireless_dev *wdev, u64 cookie, 13536 struct ieee80211_channel *chan, 13537 unsigned int duration, gfp_t gfp) 13538 { 13539 struct wiphy *wiphy = wdev->wiphy; 13540 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13541 13542 trace_cfg80211_ready_on_channel(wdev, cookie, chan, duration); 13543 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL, 13544 rdev, wdev, cookie, chan, 13545 duration, gfp); 13546 } 13547 EXPORT_SYMBOL(cfg80211_ready_on_channel); 13548 13549 void cfg80211_remain_on_channel_expired(struct wireless_dev *wdev, u64 cookie, 13550 struct ieee80211_channel *chan, 13551 gfp_t gfp) 13552 { 13553 struct wiphy *wiphy = wdev->wiphy; 13554 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13555 13556 trace_cfg80211_ready_on_channel_expired(wdev, cookie, chan); 13557 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL, 13558 rdev, wdev, cookie, chan, 0, gfp); 13559 } 13560 EXPORT_SYMBOL(cfg80211_remain_on_channel_expired); 13561 13562 void cfg80211_new_sta(struct net_device *dev, const u8 *mac_addr, 13563 struct station_info *sinfo, gfp_t gfp) 13564 { 13565 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy; 13566 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13567 struct sk_buff *msg; 13568 13569 trace_cfg80211_new_sta(dev, mac_addr, sinfo); 13570 13571 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13572 if (!msg) 13573 return; 13574 13575 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION, 0, 0, 0, 13576 rdev, dev, mac_addr, sinfo) < 0) { 13577 nlmsg_free(msg); 13578 return; 13579 } 13580 13581 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13582 NL80211_MCGRP_MLME, gfp); 13583 } 13584 EXPORT_SYMBOL(cfg80211_new_sta); 13585 13586 void cfg80211_del_sta_sinfo(struct net_device *dev, const u8 *mac_addr, 13587 struct station_info *sinfo, gfp_t gfp) 13588 { 13589 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy; 13590 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13591 struct sk_buff *msg; 13592 struct station_info empty_sinfo = {}; 13593 13594 if (!sinfo) 13595 sinfo = &empty_sinfo; 13596 13597 trace_cfg80211_del_sta(dev, mac_addr); 13598 13599 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13600 if (!msg) 13601 return; 13602 13603 if (nl80211_send_station(msg, NL80211_CMD_DEL_STATION, 0, 0, 0, 13604 rdev, dev, mac_addr, sinfo) < 0) { 13605 nlmsg_free(msg); 13606 return; 13607 } 13608 13609 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13610 NL80211_MCGRP_MLME, gfp); 13611 } 13612 EXPORT_SYMBOL(cfg80211_del_sta_sinfo); 13613 13614 void cfg80211_conn_failed(struct net_device *dev, const u8 *mac_addr, 13615 enum nl80211_connect_failed_reason reason, 13616 gfp_t gfp) 13617 { 13618 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy; 13619 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13620 struct sk_buff *msg; 13621 void *hdr; 13622 13623 msg = nlmsg_new(NLMSG_GOODSIZE, gfp); 13624 if (!msg) 13625 return; 13626 13627 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED); 13628 if (!hdr) { 13629 nlmsg_free(msg); 13630 return; 13631 } 13632 13633 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 13634 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) || 13635 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason)) 13636 goto nla_put_failure; 13637 13638 genlmsg_end(msg, hdr); 13639 13640 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13641 NL80211_MCGRP_MLME, gfp); 13642 return; 13643 13644 nla_put_failure: 13645 genlmsg_cancel(msg, hdr); 13646 nlmsg_free(msg); 13647 } 13648 EXPORT_SYMBOL(cfg80211_conn_failed); 13649 13650 static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd, 13651 const u8 *addr, gfp_t gfp) 13652 { 13653 struct wireless_dev *wdev = dev->ieee80211_ptr; 13654 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 13655 struct sk_buff *msg; 13656 void *hdr; 13657 u32 nlportid = ACCESS_ONCE(wdev->ap_unexpected_nlportid); 13658 13659 if (!nlportid) 13660 return false; 13661 13662 msg = nlmsg_new(100, gfp); 13663 if (!msg) 13664 return true; 13665 13666 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd); 13667 if (!hdr) { 13668 nlmsg_free(msg); 13669 return true; 13670 } 13671 13672 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13673 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 13674 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) 13675 goto nla_put_failure; 13676 13677 genlmsg_end(msg, hdr); 13678 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid); 13679 return true; 13680 13681 nla_put_failure: 13682 genlmsg_cancel(msg, hdr); 13683 nlmsg_free(msg); 13684 return true; 13685 } 13686 13687 bool cfg80211_rx_spurious_frame(struct net_device *dev, 13688 const u8 *addr, gfp_t gfp) 13689 { 13690 struct wireless_dev *wdev = dev->ieee80211_ptr; 13691 bool ret; 13692 13693 trace_cfg80211_rx_spurious_frame(dev, addr); 13694 13695 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP && 13696 wdev->iftype != NL80211_IFTYPE_P2P_GO)) { 13697 trace_cfg80211_return_bool(false); 13698 return false; 13699 } 13700 ret = __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME, 13701 addr, gfp); 13702 trace_cfg80211_return_bool(ret); 13703 return ret; 13704 } 13705 EXPORT_SYMBOL(cfg80211_rx_spurious_frame); 13706 13707 bool cfg80211_rx_unexpected_4addr_frame(struct net_device *dev, 13708 const u8 *addr, gfp_t gfp) 13709 { 13710 struct wireless_dev *wdev = dev->ieee80211_ptr; 13711 bool ret; 13712 13713 trace_cfg80211_rx_unexpected_4addr_frame(dev, addr); 13714 13715 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP && 13716 wdev->iftype != NL80211_IFTYPE_P2P_GO && 13717 wdev->iftype != NL80211_IFTYPE_AP_VLAN)) { 13718 trace_cfg80211_return_bool(false); 13719 return false; 13720 } 13721 ret = __nl80211_unexpected_frame(dev, 13722 NL80211_CMD_UNEXPECTED_4ADDR_FRAME, 13723 addr, gfp); 13724 trace_cfg80211_return_bool(ret); 13725 return ret; 13726 } 13727 EXPORT_SYMBOL(cfg80211_rx_unexpected_4addr_frame); 13728 13729 int nl80211_send_mgmt(struct cfg80211_registered_device *rdev, 13730 struct wireless_dev *wdev, u32 nlportid, 13731 int freq, int sig_dbm, 13732 const u8 *buf, size_t len, u32 flags, gfp_t gfp) 13733 { 13734 struct net_device *netdev = wdev->netdev; 13735 struct sk_buff *msg; 13736 void *hdr; 13737 13738 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13739 if (!msg) 13740 return -ENOMEM; 13741 13742 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME); 13743 if (!hdr) { 13744 nlmsg_free(msg); 13745 return -ENOMEM; 13746 } 13747 13748 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13749 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 13750 netdev->ifindex)) || 13751 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 13752 NL80211_ATTR_PAD) || 13753 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) || 13754 (sig_dbm && 13755 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) || 13756 nla_put(msg, NL80211_ATTR_FRAME, len, buf) || 13757 (flags && 13758 nla_put_u32(msg, NL80211_ATTR_RXMGMT_FLAGS, flags))) 13759 goto nla_put_failure; 13760 13761 genlmsg_end(msg, hdr); 13762 13763 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid); 13764 13765 nla_put_failure: 13766 genlmsg_cancel(msg, hdr); 13767 nlmsg_free(msg); 13768 return -ENOBUFS; 13769 } 13770 13771 void cfg80211_mgmt_tx_status(struct wireless_dev *wdev, u64 cookie, 13772 const u8 *buf, size_t len, bool ack, gfp_t gfp) 13773 { 13774 struct wiphy *wiphy = wdev->wiphy; 13775 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13776 struct net_device *netdev = wdev->netdev; 13777 struct sk_buff *msg; 13778 void *hdr; 13779 13780 trace_cfg80211_mgmt_tx_status(wdev, cookie, ack); 13781 13782 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13783 if (!msg) 13784 return; 13785 13786 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS); 13787 if (!hdr) { 13788 nlmsg_free(msg); 13789 return; 13790 } 13791 13792 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13793 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 13794 netdev->ifindex)) || 13795 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 13796 NL80211_ATTR_PAD) || 13797 nla_put(msg, NL80211_ATTR_FRAME, len, buf) || 13798 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 13799 NL80211_ATTR_PAD) || 13800 (ack && nla_put_flag(msg, NL80211_ATTR_ACK))) 13801 goto nla_put_failure; 13802 13803 genlmsg_end(msg, hdr); 13804 13805 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13806 NL80211_MCGRP_MLME, gfp); 13807 return; 13808 13809 nla_put_failure: 13810 genlmsg_cancel(msg, hdr); 13811 nlmsg_free(msg); 13812 } 13813 EXPORT_SYMBOL(cfg80211_mgmt_tx_status); 13814 13815 static struct sk_buff *cfg80211_prepare_cqm(struct net_device *dev, 13816 const char *mac, gfp_t gfp) 13817 { 13818 struct wireless_dev *wdev = dev->ieee80211_ptr; 13819 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 13820 struct sk_buff *msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13821 void **cb; 13822 13823 if (!msg) 13824 return NULL; 13825 13826 cb = (void **)msg->cb; 13827 13828 cb[0] = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM); 13829 if (!cb[0]) { 13830 nlmsg_free(msg); 13831 return NULL; 13832 } 13833 13834 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13835 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex)) 13836 goto nla_put_failure; 13837 13838 if (mac && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac)) 13839 goto nla_put_failure; 13840 13841 cb[1] = nla_nest_start(msg, NL80211_ATTR_CQM); 13842 if (!cb[1]) 13843 goto nla_put_failure; 13844 13845 cb[2] = rdev; 13846 13847 return msg; 13848 nla_put_failure: 13849 nlmsg_free(msg); 13850 return NULL; 13851 } 13852 13853 static void cfg80211_send_cqm(struct sk_buff *msg, gfp_t gfp) 13854 { 13855 void **cb = (void **)msg->cb; 13856 struct cfg80211_registered_device *rdev = cb[2]; 13857 13858 nla_nest_end(msg, cb[1]); 13859 genlmsg_end(msg, cb[0]); 13860 13861 memset(msg->cb, 0, sizeof(msg->cb)); 13862 13863 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13864 NL80211_MCGRP_MLME, gfp); 13865 } 13866 13867 void cfg80211_cqm_rssi_notify(struct net_device *dev, 13868 enum nl80211_cqm_rssi_threshold_event rssi_event, 13869 gfp_t gfp) 13870 { 13871 struct sk_buff *msg; 13872 13873 trace_cfg80211_cqm_rssi_notify(dev, rssi_event); 13874 13875 if (WARN_ON(rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW && 13876 rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH)) 13877 return; 13878 13879 msg = cfg80211_prepare_cqm(dev, NULL, gfp); 13880 if (!msg) 13881 return; 13882 13883 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT, 13884 rssi_event)) 13885 goto nla_put_failure; 13886 13887 cfg80211_send_cqm(msg, gfp); 13888 13889 return; 13890 13891 nla_put_failure: 13892 nlmsg_free(msg); 13893 } 13894 EXPORT_SYMBOL(cfg80211_cqm_rssi_notify); 13895 13896 void cfg80211_cqm_txe_notify(struct net_device *dev, 13897 const u8 *peer, u32 num_packets, 13898 u32 rate, u32 intvl, gfp_t gfp) 13899 { 13900 struct sk_buff *msg; 13901 13902 msg = cfg80211_prepare_cqm(dev, peer, gfp); 13903 if (!msg) 13904 return; 13905 13906 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets)) 13907 goto nla_put_failure; 13908 13909 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate)) 13910 goto nla_put_failure; 13911 13912 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl)) 13913 goto nla_put_failure; 13914 13915 cfg80211_send_cqm(msg, gfp); 13916 return; 13917 13918 nla_put_failure: 13919 nlmsg_free(msg); 13920 } 13921 EXPORT_SYMBOL(cfg80211_cqm_txe_notify); 13922 13923 void cfg80211_cqm_pktloss_notify(struct net_device *dev, 13924 const u8 *peer, u32 num_packets, gfp_t gfp) 13925 { 13926 struct sk_buff *msg; 13927 13928 trace_cfg80211_cqm_pktloss_notify(dev, peer, num_packets); 13929 13930 msg = cfg80211_prepare_cqm(dev, peer, gfp); 13931 if (!msg) 13932 return; 13933 13934 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets)) 13935 goto nla_put_failure; 13936 13937 cfg80211_send_cqm(msg, gfp); 13938 return; 13939 13940 nla_put_failure: 13941 nlmsg_free(msg); 13942 } 13943 EXPORT_SYMBOL(cfg80211_cqm_pktloss_notify); 13944 13945 void cfg80211_cqm_beacon_loss_notify(struct net_device *dev, gfp_t gfp) 13946 { 13947 struct sk_buff *msg; 13948 13949 msg = cfg80211_prepare_cqm(dev, NULL, gfp); 13950 if (!msg) 13951 return; 13952 13953 if (nla_put_flag(msg, NL80211_ATTR_CQM_BEACON_LOSS_EVENT)) 13954 goto nla_put_failure; 13955 13956 cfg80211_send_cqm(msg, gfp); 13957 return; 13958 13959 nla_put_failure: 13960 nlmsg_free(msg); 13961 } 13962 EXPORT_SYMBOL(cfg80211_cqm_beacon_loss_notify); 13963 13964 static void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev, 13965 struct net_device *netdev, const u8 *bssid, 13966 const u8 *replay_ctr, gfp_t gfp) 13967 { 13968 struct sk_buff *msg; 13969 struct nlattr *rekey_attr; 13970 void *hdr; 13971 13972 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13973 if (!msg) 13974 return; 13975 13976 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD); 13977 if (!hdr) { 13978 nlmsg_free(msg); 13979 return; 13980 } 13981 13982 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13983 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13984 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) 13985 goto nla_put_failure; 13986 13987 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA); 13988 if (!rekey_attr) 13989 goto nla_put_failure; 13990 13991 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR, 13992 NL80211_REPLAY_CTR_LEN, replay_ctr)) 13993 goto nla_put_failure; 13994 13995 nla_nest_end(msg, rekey_attr); 13996 13997 genlmsg_end(msg, hdr); 13998 13999 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14000 NL80211_MCGRP_MLME, gfp); 14001 return; 14002 14003 nla_put_failure: 14004 genlmsg_cancel(msg, hdr); 14005 nlmsg_free(msg); 14006 } 14007 14008 void cfg80211_gtk_rekey_notify(struct net_device *dev, const u8 *bssid, 14009 const u8 *replay_ctr, gfp_t gfp) 14010 { 14011 struct wireless_dev *wdev = dev->ieee80211_ptr; 14012 struct wiphy *wiphy = wdev->wiphy; 14013 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14014 14015 trace_cfg80211_gtk_rekey_notify(dev, bssid); 14016 nl80211_gtk_rekey_notify(rdev, dev, bssid, replay_ctr, gfp); 14017 } 14018 EXPORT_SYMBOL(cfg80211_gtk_rekey_notify); 14019 14020 static void 14021 nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev, 14022 struct net_device *netdev, int index, 14023 const u8 *bssid, bool preauth, gfp_t gfp) 14024 { 14025 struct sk_buff *msg; 14026 struct nlattr *attr; 14027 void *hdr; 14028 14029 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14030 if (!msg) 14031 return; 14032 14033 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE); 14034 if (!hdr) { 14035 nlmsg_free(msg); 14036 return; 14037 } 14038 14039 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14040 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex)) 14041 goto nla_put_failure; 14042 14043 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE); 14044 if (!attr) 14045 goto nla_put_failure; 14046 14047 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) || 14048 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) || 14049 (preauth && 14050 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH))) 14051 goto nla_put_failure; 14052 14053 nla_nest_end(msg, attr); 14054 14055 genlmsg_end(msg, hdr); 14056 14057 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14058 NL80211_MCGRP_MLME, gfp); 14059 return; 14060 14061 nla_put_failure: 14062 genlmsg_cancel(msg, hdr); 14063 nlmsg_free(msg); 14064 } 14065 14066 void cfg80211_pmksa_candidate_notify(struct net_device *dev, int index, 14067 const u8 *bssid, bool preauth, gfp_t gfp) 14068 { 14069 struct wireless_dev *wdev = dev->ieee80211_ptr; 14070 struct wiphy *wiphy = wdev->wiphy; 14071 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14072 14073 trace_cfg80211_pmksa_candidate_notify(dev, index, bssid, preauth); 14074 nl80211_pmksa_candidate_notify(rdev, dev, index, bssid, preauth, gfp); 14075 } 14076 EXPORT_SYMBOL(cfg80211_pmksa_candidate_notify); 14077 14078 static void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev, 14079 struct net_device *netdev, 14080 struct cfg80211_chan_def *chandef, 14081 gfp_t gfp, 14082 enum nl80211_commands notif, 14083 u8 count) 14084 { 14085 struct sk_buff *msg; 14086 void *hdr; 14087 14088 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14089 if (!msg) 14090 return; 14091 14092 hdr = nl80211hdr_put(msg, 0, 0, 0, notif); 14093 if (!hdr) { 14094 nlmsg_free(msg); 14095 return; 14096 } 14097 14098 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex)) 14099 goto nla_put_failure; 14100 14101 if (nl80211_send_chandef(msg, chandef)) 14102 goto nla_put_failure; 14103 14104 if ((notif == NL80211_CMD_CH_SWITCH_STARTED_NOTIFY) && 14105 (nla_put_u32(msg, NL80211_ATTR_CH_SWITCH_COUNT, count))) 14106 goto nla_put_failure; 14107 14108 genlmsg_end(msg, hdr); 14109 14110 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14111 NL80211_MCGRP_MLME, gfp); 14112 return; 14113 14114 nla_put_failure: 14115 genlmsg_cancel(msg, hdr); 14116 nlmsg_free(msg); 14117 } 14118 14119 void cfg80211_ch_switch_notify(struct net_device *dev, 14120 struct cfg80211_chan_def *chandef) 14121 { 14122 struct wireless_dev *wdev = dev->ieee80211_ptr; 14123 struct wiphy *wiphy = wdev->wiphy; 14124 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14125 14126 ASSERT_WDEV_LOCK(wdev); 14127 14128 trace_cfg80211_ch_switch_notify(dev, chandef); 14129 14130 wdev->chandef = *chandef; 14131 wdev->preset_chandef = *chandef; 14132 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL, 14133 NL80211_CMD_CH_SWITCH_NOTIFY, 0); 14134 } 14135 EXPORT_SYMBOL(cfg80211_ch_switch_notify); 14136 14137 void cfg80211_ch_switch_started_notify(struct net_device *dev, 14138 struct cfg80211_chan_def *chandef, 14139 u8 count) 14140 { 14141 struct wireless_dev *wdev = dev->ieee80211_ptr; 14142 struct wiphy *wiphy = wdev->wiphy; 14143 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14144 14145 trace_cfg80211_ch_switch_started_notify(dev, chandef); 14146 14147 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL, 14148 NL80211_CMD_CH_SWITCH_STARTED_NOTIFY, count); 14149 } 14150 EXPORT_SYMBOL(cfg80211_ch_switch_started_notify); 14151 14152 void 14153 nl80211_radar_notify(struct cfg80211_registered_device *rdev, 14154 const struct cfg80211_chan_def *chandef, 14155 enum nl80211_radar_event event, 14156 struct net_device *netdev, gfp_t gfp) 14157 { 14158 struct sk_buff *msg; 14159 void *hdr; 14160 14161 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14162 if (!msg) 14163 return; 14164 14165 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_RADAR_DETECT); 14166 if (!hdr) { 14167 nlmsg_free(msg); 14168 return; 14169 } 14170 14171 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx)) 14172 goto nla_put_failure; 14173 14174 /* NOP and radar events don't need a netdev parameter */ 14175 if (netdev) { 14176 struct wireless_dev *wdev = netdev->ieee80211_ptr; 14177 14178 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 14179 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 14180 NL80211_ATTR_PAD)) 14181 goto nla_put_failure; 14182 } 14183 14184 if (nla_put_u32(msg, NL80211_ATTR_RADAR_EVENT, event)) 14185 goto nla_put_failure; 14186 14187 if (nl80211_send_chandef(msg, chandef)) 14188 goto nla_put_failure; 14189 14190 genlmsg_end(msg, hdr); 14191 14192 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14193 NL80211_MCGRP_MLME, gfp); 14194 return; 14195 14196 nla_put_failure: 14197 genlmsg_cancel(msg, hdr); 14198 nlmsg_free(msg); 14199 } 14200 14201 void cfg80211_probe_status(struct net_device *dev, const u8 *addr, 14202 u64 cookie, bool acked, gfp_t gfp) 14203 { 14204 struct wireless_dev *wdev = dev->ieee80211_ptr; 14205 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 14206 struct sk_buff *msg; 14207 void *hdr; 14208 14209 trace_cfg80211_probe_status(dev, addr, cookie, acked); 14210 14211 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14212 14213 if (!msg) 14214 return; 14215 14216 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT); 14217 if (!hdr) { 14218 nlmsg_free(msg); 14219 return; 14220 } 14221 14222 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14223 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 14224 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) || 14225 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 14226 NL80211_ATTR_PAD) || 14227 (acked && nla_put_flag(msg, NL80211_ATTR_ACK))) 14228 goto nla_put_failure; 14229 14230 genlmsg_end(msg, hdr); 14231 14232 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14233 NL80211_MCGRP_MLME, gfp); 14234 return; 14235 14236 nla_put_failure: 14237 genlmsg_cancel(msg, hdr); 14238 nlmsg_free(msg); 14239 } 14240 EXPORT_SYMBOL(cfg80211_probe_status); 14241 14242 void cfg80211_report_obss_beacon(struct wiphy *wiphy, 14243 const u8 *frame, size_t len, 14244 int freq, int sig_dbm) 14245 { 14246 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14247 struct sk_buff *msg; 14248 void *hdr; 14249 struct cfg80211_beacon_registration *reg; 14250 14251 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm); 14252 14253 spin_lock_bh(&rdev->beacon_registrations_lock); 14254 list_for_each_entry(reg, &rdev->beacon_registrations, list) { 14255 msg = nlmsg_new(len + 100, GFP_ATOMIC); 14256 if (!msg) { 14257 spin_unlock_bh(&rdev->beacon_registrations_lock); 14258 return; 14259 } 14260 14261 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME); 14262 if (!hdr) 14263 goto nla_put_failure; 14264 14265 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14266 (freq && 14267 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) || 14268 (sig_dbm && 14269 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) || 14270 nla_put(msg, NL80211_ATTR_FRAME, len, frame)) 14271 goto nla_put_failure; 14272 14273 genlmsg_end(msg, hdr); 14274 14275 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid); 14276 } 14277 spin_unlock_bh(&rdev->beacon_registrations_lock); 14278 return; 14279 14280 nla_put_failure: 14281 spin_unlock_bh(&rdev->beacon_registrations_lock); 14282 if (hdr) 14283 genlmsg_cancel(msg, hdr); 14284 nlmsg_free(msg); 14285 } 14286 EXPORT_SYMBOL(cfg80211_report_obss_beacon); 14287 14288 #ifdef CONFIG_PM 14289 static int cfg80211_net_detect_results(struct sk_buff *msg, 14290 struct cfg80211_wowlan_wakeup *wakeup) 14291 { 14292 struct cfg80211_wowlan_nd_info *nd = wakeup->net_detect; 14293 struct nlattr *nl_results, *nl_match, *nl_freqs; 14294 int i, j; 14295 14296 nl_results = nla_nest_start( 14297 msg, NL80211_WOWLAN_TRIG_NET_DETECT_RESULTS); 14298 if (!nl_results) 14299 return -EMSGSIZE; 14300 14301 for (i = 0; i < nd->n_matches; i++) { 14302 struct cfg80211_wowlan_nd_match *match = nd->matches[i]; 14303 14304 nl_match = nla_nest_start(msg, i); 14305 if (!nl_match) 14306 break; 14307 14308 /* The SSID attribute is optional in nl80211, but for 14309 * simplicity reasons it's always present in the 14310 * cfg80211 structure. If a driver can't pass the 14311 * SSID, that needs to be changed. A zero length SSID 14312 * is still a valid SSID (wildcard), so it cannot be 14313 * used for this purpose. 14314 */ 14315 if (nla_put(msg, NL80211_ATTR_SSID, match->ssid.ssid_len, 14316 match->ssid.ssid)) { 14317 nla_nest_cancel(msg, nl_match); 14318 goto out; 14319 } 14320 14321 if (match->n_channels) { 14322 nl_freqs = nla_nest_start( 14323 msg, NL80211_ATTR_SCAN_FREQUENCIES); 14324 if (!nl_freqs) { 14325 nla_nest_cancel(msg, nl_match); 14326 goto out; 14327 } 14328 14329 for (j = 0; j < match->n_channels; j++) { 14330 if (nla_put_u32(msg, j, match->channels[j])) { 14331 nla_nest_cancel(msg, nl_freqs); 14332 nla_nest_cancel(msg, nl_match); 14333 goto out; 14334 } 14335 } 14336 14337 nla_nest_end(msg, nl_freqs); 14338 } 14339 14340 nla_nest_end(msg, nl_match); 14341 } 14342 14343 out: 14344 nla_nest_end(msg, nl_results); 14345 return 0; 14346 } 14347 14348 void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev, 14349 struct cfg80211_wowlan_wakeup *wakeup, 14350 gfp_t gfp) 14351 { 14352 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 14353 struct sk_buff *msg; 14354 void *hdr; 14355 int size = 200; 14356 14357 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup); 14358 14359 if (wakeup) 14360 size += wakeup->packet_present_len; 14361 14362 msg = nlmsg_new(size, gfp); 14363 if (!msg) 14364 return; 14365 14366 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN); 14367 if (!hdr) 14368 goto free_msg; 14369 14370 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14371 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 14372 NL80211_ATTR_PAD)) 14373 goto free_msg; 14374 14375 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 14376 wdev->netdev->ifindex)) 14377 goto free_msg; 14378 14379 if (wakeup) { 14380 struct nlattr *reasons; 14381 14382 reasons = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS); 14383 if (!reasons) 14384 goto free_msg; 14385 14386 if (wakeup->disconnect && 14387 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) 14388 goto free_msg; 14389 if (wakeup->magic_pkt && 14390 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) 14391 goto free_msg; 14392 if (wakeup->gtk_rekey_failure && 14393 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) 14394 goto free_msg; 14395 if (wakeup->eap_identity_req && 14396 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) 14397 goto free_msg; 14398 if (wakeup->four_way_handshake && 14399 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) 14400 goto free_msg; 14401 if (wakeup->rfkill_release && 14402 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)) 14403 goto free_msg; 14404 14405 if (wakeup->pattern_idx >= 0 && 14406 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN, 14407 wakeup->pattern_idx)) 14408 goto free_msg; 14409 14410 if (wakeup->tcp_match && 14411 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_MATCH)) 14412 goto free_msg; 14413 14414 if (wakeup->tcp_connlost && 14415 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_CONNLOST)) 14416 goto free_msg; 14417 14418 if (wakeup->tcp_nomoretokens && 14419 nla_put_flag(msg, 14420 NL80211_WOWLAN_TRIG_WAKEUP_TCP_NOMORETOKENS)) 14421 goto free_msg; 14422 14423 if (wakeup->packet) { 14424 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211; 14425 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN; 14426 14427 if (!wakeup->packet_80211) { 14428 pkt_attr = 14429 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023; 14430 len_attr = 14431 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN; 14432 } 14433 14434 if (wakeup->packet_len && 14435 nla_put_u32(msg, len_attr, wakeup->packet_len)) 14436 goto free_msg; 14437 14438 if (nla_put(msg, pkt_attr, wakeup->packet_present_len, 14439 wakeup->packet)) 14440 goto free_msg; 14441 } 14442 14443 if (wakeup->net_detect && 14444 cfg80211_net_detect_results(msg, wakeup)) 14445 goto free_msg; 14446 14447 nla_nest_end(msg, reasons); 14448 } 14449 14450 genlmsg_end(msg, hdr); 14451 14452 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14453 NL80211_MCGRP_MLME, gfp); 14454 return; 14455 14456 free_msg: 14457 nlmsg_free(msg); 14458 } 14459 EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup); 14460 #endif 14461 14462 void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer, 14463 enum nl80211_tdls_operation oper, 14464 u16 reason_code, gfp_t gfp) 14465 { 14466 struct wireless_dev *wdev = dev->ieee80211_ptr; 14467 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 14468 struct sk_buff *msg; 14469 void *hdr; 14470 14471 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper, 14472 reason_code); 14473 14474 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14475 if (!msg) 14476 return; 14477 14478 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER); 14479 if (!hdr) { 14480 nlmsg_free(msg); 14481 return; 14482 } 14483 14484 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14485 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 14486 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) || 14487 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) || 14488 (reason_code > 0 && 14489 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code))) 14490 goto nla_put_failure; 14491 14492 genlmsg_end(msg, hdr); 14493 14494 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14495 NL80211_MCGRP_MLME, gfp); 14496 return; 14497 14498 nla_put_failure: 14499 genlmsg_cancel(msg, hdr); 14500 nlmsg_free(msg); 14501 } 14502 EXPORT_SYMBOL(cfg80211_tdls_oper_request); 14503 14504 static int nl80211_netlink_notify(struct notifier_block * nb, 14505 unsigned long state, 14506 void *_notify) 14507 { 14508 struct netlink_notify *notify = _notify; 14509 struct cfg80211_registered_device *rdev; 14510 struct wireless_dev *wdev; 14511 struct cfg80211_beacon_registration *reg, *tmp; 14512 14513 if (state != NETLINK_URELEASE || notify->protocol != NETLINK_GENERIC) 14514 return NOTIFY_DONE; 14515 14516 rcu_read_lock(); 14517 14518 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) { 14519 bool schedule_destroy_work = false; 14520 struct cfg80211_sched_scan_request *sched_scan_req = 14521 rcu_dereference(rdev->sched_scan_req); 14522 14523 if (sched_scan_req && notify->portid && 14524 sched_scan_req->owner_nlportid == notify->portid) { 14525 sched_scan_req->owner_nlportid = 0; 14526 14527 if (rdev->ops->sched_scan_stop && 14528 rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) 14529 schedule_work(&rdev->sched_scan_stop_wk); 14530 } 14531 14532 list_for_each_entry_rcu(wdev, &rdev->wiphy.wdev_list, list) { 14533 cfg80211_mlme_unregister_socket(wdev, notify->portid); 14534 14535 if (wdev->owner_nlportid == notify->portid) 14536 schedule_destroy_work = true; 14537 } 14538 14539 spin_lock_bh(&rdev->beacon_registrations_lock); 14540 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations, 14541 list) { 14542 if (reg->nlportid == notify->portid) { 14543 list_del(®->list); 14544 kfree(reg); 14545 break; 14546 } 14547 } 14548 spin_unlock_bh(&rdev->beacon_registrations_lock); 14549 14550 if (schedule_destroy_work) { 14551 struct cfg80211_iface_destroy *destroy; 14552 14553 destroy = kzalloc(sizeof(*destroy), GFP_ATOMIC); 14554 if (destroy) { 14555 destroy->nlportid = notify->portid; 14556 spin_lock(&rdev->destroy_list_lock); 14557 list_add(&destroy->list, &rdev->destroy_list); 14558 spin_unlock(&rdev->destroy_list_lock); 14559 schedule_work(&rdev->destroy_work); 14560 } 14561 } 14562 } 14563 14564 rcu_read_unlock(); 14565 14566 /* 14567 * It is possible that the user space process that is controlling the 14568 * indoor setting disappeared, so notify the regulatory core. 14569 */ 14570 regulatory_netlink_notify(notify->portid); 14571 return NOTIFY_OK; 14572 } 14573 14574 static struct notifier_block nl80211_netlink_notifier = { 14575 .notifier_call = nl80211_netlink_notify, 14576 }; 14577 14578 void cfg80211_ft_event(struct net_device *netdev, 14579 struct cfg80211_ft_event_params *ft_event) 14580 { 14581 struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy; 14582 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14583 struct sk_buff *msg; 14584 void *hdr; 14585 14586 trace_cfg80211_ft_event(wiphy, netdev, ft_event); 14587 14588 if (!ft_event->target_ap) 14589 return; 14590 14591 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 14592 if (!msg) 14593 return; 14594 14595 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FT_EVENT); 14596 if (!hdr) 14597 goto out; 14598 14599 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14600 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 14601 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, ft_event->target_ap)) 14602 goto out; 14603 14604 if (ft_event->ies && 14605 nla_put(msg, NL80211_ATTR_IE, ft_event->ies_len, ft_event->ies)) 14606 goto out; 14607 if (ft_event->ric_ies && 14608 nla_put(msg, NL80211_ATTR_IE_RIC, ft_event->ric_ies_len, 14609 ft_event->ric_ies)) 14610 goto out; 14611 14612 genlmsg_end(msg, hdr); 14613 14614 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14615 NL80211_MCGRP_MLME, GFP_KERNEL); 14616 return; 14617 out: 14618 nlmsg_free(msg); 14619 } 14620 EXPORT_SYMBOL(cfg80211_ft_event); 14621 14622 void cfg80211_crit_proto_stopped(struct wireless_dev *wdev, gfp_t gfp) 14623 { 14624 struct cfg80211_registered_device *rdev; 14625 struct sk_buff *msg; 14626 void *hdr; 14627 u32 nlportid; 14628 14629 rdev = wiphy_to_rdev(wdev->wiphy); 14630 if (!rdev->crit_proto_nlportid) 14631 return; 14632 14633 nlportid = rdev->crit_proto_nlportid; 14634 rdev->crit_proto_nlportid = 0; 14635 14636 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14637 if (!msg) 14638 return; 14639 14640 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CRIT_PROTOCOL_STOP); 14641 if (!hdr) 14642 goto nla_put_failure; 14643 14644 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14645 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 14646 NL80211_ATTR_PAD)) 14647 goto nla_put_failure; 14648 14649 genlmsg_end(msg, hdr); 14650 14651 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid); 14652 return; 14653 14654 nla_put_failure: 14655 if (hdr) 14656 genlmsg_cancel(msg, hdr); 14657 nlmsg_free(msg); 14658 } 14659 EXPORT_SYMBOL(cfg80211_crit_proto_stopped); 14660 14661 void nl80211_send_ap_stopped(struct wireless_dev *wdev) 14662 { 14663 struct wiphy *wiphy = wdev->wiphy; 14664 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14665 struct sk_buff *msg; 14666 void *hdr; 14667 14668 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 14669 if (!msg) 14670 return; 14671 14672 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_STOP_AP); 14673 if (!hdr) 14674 goto out; 14675 14676 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14677 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex) || 14678 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 14679 NL80211_ATTR_PAD)) 14680 goto out; 14681 14682 genlmsg_end(msg, hdr); 14683 14684 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(wiphy), msg, 0, 14685 NL80211_MCGRP_MLME, GFP_KERNEL); 14686 return; 14687 out: 14688 nlmsg_free(msg); 14689 } 14690 14691 /* initialisation/exit functions */ 14692 14693 int __init nl80211_init(void) 14694 { 14695 int err; 14696 14697 err = genl_register_family(&nl80211_fam); 14698 if (err) 14699 return err; 14700 14701 err = netlink_register_notifier(&nl80211_netlink_notifier); 14702 if (err) 14703 goto err_out; 14704 14705 return 0; 14706 err_out: 14707 genl_unregister_family(&nl80211_fam); 14708 return err; 14709 } 14710 14711 void nl80211_exit(void) 14712 { 14713 netlink_unregister_notifier(&nl80211_netlink_notifier); 14714 genl_unregister_family(&nl80211_fam); 14715 } 14716