nl80211: fix overflow in ssid_len
[linux-2.6/linux-acpi-2.6/ibm-acpi-2.6.git] / net / wireless / nl80211.c
blobdbb6dde6b30506b003846e64667058c514d2f18d
1 /*
2 * This is the new netlink-based wireless configuration interface.
4 * Copyright 2006-2009 Johannes Berg <johannes@sipsolutions.net>
5 */
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/list.h>
11 #include <linux/if_ether.h>
12 #include <linux/ieee80211.h>
13 #include <linux/nl80211.h>
14 #include <linux/rtnetlink.h>
15 #include <linux/netlink.h>
16 #include <linux/etherdevice.h>
17 #include <net/net_namespace.h>
18 #include <net/genetlink.h>
19 #include <net/cfg80211.h>
20 #include <net/sock.h>
21 #include "core.h"
22 #include "nl80211.h"
23 #include "reg.h"
25 /* the netlink family */
26 static struct genl_family nl80211_fam = {
27 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
28 .name = "nl80211", /* have users key off the name instead */
29 .hdrsize = 0, /* no private header */
30 .version = 1, /* no particular meaning now */
31 .maxattr = NL80211_ATTR_MAX,
32 .netnsok = true,
35 /* internal helper: get rdev and dev */
36 static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
37 struct cfg80211_registered_device **rdev,
38 struct net_device **dev)
40 struct nlattr **attrs = info->attrs;
41 int ifindex;
43 if (!attrs[NL80211_ATTR_IFINDEX])
44 return -EINVAL;
46 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
47 *dev = dev_get_by_index(genl_info_net(info), ifindex);
48 if (!*dev)
49 return -ENODEV;
51 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
52 if (IS_ERR(*rdev)) {
53 dev_put(*dev);
54 return PTR_ERR(*rdev);
57 return 0;
60 /* policy for the attributes */
61 static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
62 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
63 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
64 .len = 20-1 },
65 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
66 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
67 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
68 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
69 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
70 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
71 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
73 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
74 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
75 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
77 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
78 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
80 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
81 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
82 .len = WLAN_MAX_KEY_LEN },
83 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
84 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
85 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
86 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
88 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
89 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
90 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
91 .len = IEEE80211_MAX_DATA_LEN },
92 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
93 .len = IEEE80211_MAX_DATA_LEN },
94 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
95 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
96 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
97 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
98 .len = NL80211_MAX_SUPP_RATES },
99 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
100 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
101 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
102 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
103 .len = IEEE80211_MAX_MESH_ID_LEN },
104 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
106 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
107 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
109 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
110 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
111 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
112 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
113 .len = NL80211_MAX_SUPP_RATES },
115 [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
117 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
118 .len = NL80211_HT_CAPABILITY_LEN },
120 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
121 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
122 .len = IEEE80211_MAX_DATA_LEN },
123 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
124 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
126 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
127 .len = IEEE80211_MAX_SSID_LEN },
128 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
129 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
130 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
131 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
132 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
133 [NL80211_ATTR_STA_FLAGS2] = {
134 .len = sizeof(struct nl80211_sta_flag_update),
136 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
137 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
138 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
139 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
140 [NL80211_ATTR_PID] = { .type = NLA_U32 },
143 /* policy for the attributes */
144 static struct nla_policy
145 nl80211_key_policy[NL80211_KEY_MAX + 1] __read_mostly = {
146 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
147 [NL80211_KEY_IDX] = { .type = NLA_U8 },
148 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
149 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
150 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
151 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
154 /* IE validation */
155 static bool is_valid_ie_attr(const struct nlattr *attr)
157 const u8 *pos;
158 int len;
160 if (!attr)
161 return true;
163 pos = nla_data(attr);
164 len = nla_len(attr);
166 while (len) {
167 u8 elemlen;
169 if (len < 2)
170 return false;
171 len -= 2;
173 elemlen = pos[1];
174 if (elemlen > len)
175 return false;
177 len -= elemlen;
178 pos += 2 + elemlen;
181 return true;
184 /* message building helper */
185 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
186 int flags, u8 cmd)
188 /* since there is no private header just add the generic one */
189 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
192 static int nl80211_msg_put_channel(struct sk_buff *msg,
193 struct ieee80211_channel *chan)
195 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
196 chan->center_freq);
198 if (chan->flags & IEEE80211_CHAN_DISABLED)
199 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
200 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
201 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
202 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
203 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
204 if (chan->flags & IEEE80211_CHAN_RADAR)
205 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
207 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
208 DBM_TO_MBM(chan->max_power));
210 return 0;
212 nla_put_failure:
213 return -ENOBUFS;
216 /* netlink command implementations */
218 struct key_parse {
219 struct key_params p;
220 int idx;
221 bool def, defmgmt;
224 static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
226 struct nlattr *tb[NL80211_KEY_MAX + 1];
227 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
228 nl80211_key_policy);
229 if (err)
230 return err;
232 k->def = !!tb[NL80211_KEY_DEFAULT];
233 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
235 if (tb[NL80211_KEY_IDX])
236 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
238 if (tb[NL80211_KEY_DATA]) {
239 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
240 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
243 if (tb[NL80211_KEY_SEQ]) {
244 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
245 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
248 if (tb[NL80211_KEY_CIPHER])
249 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
251 return 0;
254 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
256 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
257 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
258 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
261 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
262 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
263 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
266 if (info->attrs[NL80211_ATTR_KEY_IDX])
267 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
269 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
270 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
272 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
273 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
275 return 0;
278 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
280 int err;
282 memset(k, 0, sizeof(*k));
283 k->idx = -1;
285 if (info->attrs[NL80211_ATTR_KEY])
286 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
287 else
288 err = nl80211_parse_key_old(info, k);
290 if (err)
291 return err;
293 if (k->def && k->defmgmt)
294 return -EINVAL;
296 if (k->idx != -1) {
297 if (k->defmgmt) {
298 if (k->idx < 4 || k->idx > 5)
299 return -EINVAL;
300 } else if (k->def) {
301 if (k->idx < 0 || k->idx > 3)
302 return -EINVAL;
303 } else {
304 if (k->idx < 0 || k->idx > 5)
305 return -EINVAL;
309 return 0;
312 static struct cfg80211_cached_keys *
313 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
314 struct nlattr *keys)
316 struct key_parse parse;
317 struct nlattr *key;
318 struct cfg80211_cached_keys *result;
319 int rem, err, def = 0;
321 result = kzalloc(sizeof(*result), GFP_KERNEL);
322 if (!result)
323 return ERR_PTR(-ENOMEM);
325 result->def = -1;
326 result->defmgmt = -1;
328 nla_for_each_nested(key, keys, rem) {
329 memset(&parse, 0, sizeof(parse));
330 parse.idx = -1;
332 err = nl80211_parse_key_new(key, &parse);
333 if (err)
334 goto error;
335 err = -EINVAL;
336 if (!parse.p.key)
337 goto error;
338 if (parse.idx < 0 || parse.idx > 4)
339 goto error;
340 if (parse.def) {
341 if (def)
342 goto error;
343 def = 1;
344 result->def = parse.idx;
345 } else if (parse.defmgmt)
346 goto error;
347 err = cfg80211_validate_key_settings(rdev, &parse.p,
348 parse.idx, NULL);
349 if (err)
350 goto error;
351 result->params[parse.idx].cipher = parse.p.cipher;
352 result->params[parse.idx].key_len = parse.p.key_len;
353 result->params[parse.idx].key = result->data[parse.idx];
354 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
357 return result;
358 error:
359 kfree(result);
360 return ERR_PTR(err);
363 static int nl80211_key_allowed(struct wireless_dev *wdev)
365 ASSERT_WDEV_LOCK(wdev);
367 if (!netif_running(wdev->netdev))
368 return -ENETDOWN;
370 switch (wdev->iftype) {
371 case NL80211_IFTYPE_AP:
372 case NL80211_IFTYPE_AP_VLAN:
373 break;
374 case NL80211_IFTYPE_ADHOC:
375 if (!wdev->current_bss)
376 return -ENOLINK;
377 break;
378 case NL80211_IFTYPE_STATION:
379 if (wdev->sme_state != CFG80211_SME_CONNECTED)
380 return -ENOLINK;
381 break;
382 default:
383 return -EINVAL;
386 return 0;
389 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
390 struct cfg80211_registered_device *dev)
392 void *hdr;
393 struct nlattr *nl_bands, *nl_band;
394 struct nlattr *nl_freqs, *nl_freq;
395 struct nlattr *nl_rates, *nl_rate;
396 struct nlattr *nl_modes;
397 struct nlattr *nl_cmds;
398 enum ieee80211_band band;
399 struct ieee80211_channel *chan;
400 struct ieee80211_rate *rate;
401 int i;
402 u16 ifmodes = dev->wiphy.interface_modes;
404 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
405 if (!hdr)
406 return -1;
408 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
409 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
411 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
412 cfg80211_rdev_list_generation);
414 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
415 dev->wiphy.retry_short);
416 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
417 dev->wiphy.retry_long);
418 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
419 dev->wiphy.frag_threshold);
420 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
421 dev->wiphy.rts_threshold);
423 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
424 dev->wiphy.max_scan_ssids);
425 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
426 dev->wiphy.max_scan_ie_len);
428 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
429 sizeof(u32) * dev->wiphy.n_cipher_suites,
430 dev->wiphy.cipher_suites);
432 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
433 if (!nl_modes)
434 goto nla_put_failure;
436 i = 0;
437 while (ifmodes) {
438 if (ifmodes & 1)
439 NLA_PUT_FLAG(msg, i);
440 ifmodes >>= 1;
441 i++;
444 nla_nest_end(msg, nl_modes);
446 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
447 if (!nl_bands)
448 goto nla_put_failure;
450 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
451 if (!dev->wiphy.bands[band])
452 continue;
454 nl_band = nla_nest_start(msg, band);
455 if (!nl_band)
456 goto nla_put_failure;
458 /* add HT info */
459 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
460 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
461 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
462 &dev->wiphy.bands[band]->ht_cap.mcs);
463 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
464 dev->wiphy.bands[band]->ht_cap.cap);
465 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
466 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
467 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
468 dev->wiphy.bands[band]->ht_cap.ampdu_density);
471 /* add frequencies */
472 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
473 if (!nl_freqs)
474 goto nla_put_failure;
476 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
477 nl_freq = nla_nest_start(msg, i);
478 if (!nl_freq)
479 goto nla_put_failure;
481 chan = &dev->wiphy.bands[band]->channels[i];
483 if (nl80211_msg_put_channel(msg, chan))
484 goto nla_put_failure;
486 nla_nest_end(msg, nl_freq);
489 nla_nest_end(msg, nl_freqs);
491 /* add bitrates */
492 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
493 if (!nl_rates)
494 goto nla_put_failure;
496 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
497 nl_rate = nla_nest_start(msg, i);
498 if (!nl_rate)
499 goto nla_put_failure;
501 rate = &dev->wiphy.bands[band]->bitrates[i];
502 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
503 rate->bitrate);
504 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
505 NLA_PUT_FLAG(msg,
506 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
508 nla_nest_end(msg, nl_rate);
511 nla_nest_end(msg, nl_rates);
513 nla_nest_end(msg, nl_band);
515 nla_nest_end(msg, nl_bands);
517 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
518 if (!nl_cmds)
519 goto nla_put_failure;
521 i = 0;
522 #define CMD(op, n) \
523 do { \
524 if (dev->ops->op) { \
525 i++; \
526 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
528 } while (0)
530 CMD(add_virtual_intf, NEW_INTERFACE);
531 CMD(change_virtual_intf, SET_INTERFACE);
532 CMD(add_key, NEW_KEY);
533 CMD(add_beacon, NEW_BEACON);
534 CMD(add_station, NEW_STATION);
535 CMD(add_mpath, NEW_MPATH);
536 CMD(set_mesh_params, SET_MESH_PARAMS);
537 CMD(change_bss, SET_BSS);
538 CMD(auth, AUTHENTICATE);
539 CMD(assoc, ASSOCIATE);
540 CMD(deauth, DEAUTHENTICATE);
541 CMD(disassoc, DISASSOCIATE);
542 CMD(join_ibss, JOIN_IBSS);
543 if (dev->wiphy.netnsok) {
544 i++;
545 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
548 #undef CMD
550 if (dev->ops->connect || dev->ops->auth) {
551 i++;
552 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
555 if (dev->ops->disconnect || dev->ops->deauth) {
556 i++;
557 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
560 nla_nest_end(msg, nl_cmds);
562 return genlmsg_end(msg, hdr);
564 nla_put_failure:
565 genlmsg_cancel(msg, hdr);
566 return -EMSGSIZE;
569 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
571 int idx = 0;
572 int start = cb->args[0];
573 struct cfg80211_registered_device *dev;
575 mutex_lock(&cfg80211_mutex);
576 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
577 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
578 continue;
579 if (++idx <= start)
580 continue;
581 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
582 cb->nlh->nlmsg_seq, NLM_F_MULTI,
583 dev) < 0) {
584 idx--;
585 break;
588 mutex_unlock(&cfg80211_mutex);
590 cb->args[0] = idx;
592 return skb->len;
595 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
597 struct sk_buff *msg;
598 struct cfg80211_registered_device *dev;
600 dev = cfg80211_get_dev_from_info(info);
601 if (IS_ERR(dev))
602 return PTR_ERR(dev);
604 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
605 if (!msg)
606 goto out_err;
608 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
609 goto out_free;
611 cfg80211_unlock_rdev(dev);
613 return genlmsg_reply(msg, info);
615 out_free:
616 nlmsg_free(msg);
617 out_err:
618 cfg80211_unlock_rdev(dev);
619 return -ENOBUFS;
622 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
623 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
624 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
625 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
626 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
627 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
630 static int parse_txq_params(struct nlattr *tb[],
631 struct ieee80211_txq_params *txq_params)
633 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
634 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
635 !tb[NL80211_TXQ_ATTR_AIFS])
636 return -EINVAL;
638 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
639 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
640 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
641 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
642 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
644 return 0;
647 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
649 struct cfg80211_registered_device *rdev;
650 int result = 0, rem_txq_params = 0;
651 struct nlattr *nl_txq_params;
652 u32 changed;
653 u8 retry_short = 0, retry_long = 0;
654 u32 frag_threshold = 0, rts_threshold = 0;
656 rtnl_lock();
658 mutex_lock(&cfg80211_mutex);
660 rdev = __cfg80211_rdev_from_info(info);
661 if (IS_ERR(rdev)) {
662 mutex_unlock(&cfg80211_mutex);
663 result = PTR_ERR(rdev);
664 goto unlock;
667 mutex_lock(&rdev->mtx);
669 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
670 result = cfg80211_dev_rename(
671 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
673 mutex_unlock(&cfg80211_mutex);
675 if (result)
676 goto bad_res;
678 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
679 struct ieee80211_txq_params txq_params;
680 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
682 if (!rdev->ops->set_txq_params) {
683 result = -EOPNOTSUPP;
684 goto bad_res;
687 nla_for_each_nested(nl_txq_params,
688 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
689 rem_txq_params) {
690 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
691 nla_data(nl_txq_params),
692 nla_len(nl_txq_params),
693 txq_params_policy);
694 result = parse_txq_params(tb, &txq_params);
695 if (result)
696 goto bad_res;
698 result = rdev->ops->set_txq_params(&rdev->wiphy,
699 &txq_params);
700 if (result)
701 goto bad_res;
705 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
706 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
707 u32 freq;
709 result = -EINVAL;
711 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
712 channel_type = nla_get_u32(info->attrs[
713 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
714 if (channel_type != NL80211_CHAN_NO_HT &&
715 channel_type != NL80211_CHAN_HT20 &&
716 channel_type != NL80211_CHAN_HT40PLUS &&
717 channel_type != NL80211_CHAN_HT40MINUS)
718 goto bad_res;
721 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
723 mutex_lock(&rdev->devlist_mtx);
724 result = rdev_set_freq(rdev, NULL, freq, channel_type);
725 mutex_unlock(&rdev->devlist_mtx);
726 if (result)
727 goto bad_res;
730 changed = 0;
732 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
733 retry_short = nla_get_u8(
734 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
735 if (retry_short == 0) {
736 result = -EINVAL;
737 goto bad_res;
739 changed |= WIPHY_PARAM_RETRY_SHORT;
742 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
743 retry_long = nla_get_u8(
744 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
745 if (retry_long == 0) {
746 result = -EINVAL;
747 goto bad_res;
749 changed |= WIPHY_PARAM_RETRY_LONG;
752 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
753 frag_threshold = nla_get_u32(
754 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
755 if (frag_threshold < 256) {
756 result = -EINVAL;
757 goto bad_res;
759 if (frag_threshold != (u32) -1) {
761 * Fragments (apart from the last one) are required to
762 * have even length. Make the fragmentation code
763 * simpler by stripping LSB should someone try to use
764 * odd threshold value.
766 frag_threshold &= ~0x1;
768 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
771 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
772 rts_threshold = nla_get_u32(
773 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
774 changed |= WIPHY_PARAM_RTS_THRESHOLD;
777 if (changed) {
778 u8 old_retry_short, old_retry_long;
779 u32 old_frag_threshold, old_rts_threshold;
781 if (!rdev->ops->set_wiphy_params) {
782 result = -EOPNOTSUPP;
783 goto bad_res;
786 old_retry_short = rdev->wiphy.retry_short;
787 old_retry_long = rdev->wiphy.retry_long;
788 old_frag_threshold = rdev->wiphy.frag_threshold;
789 old_rts_threshold = rdev->wiphy.rts_threshold;
791 if (changed & WIPHY_PARAM_RETRY_SHORT)
792 rdev->wiphy.retry_short = retry_short;
793 if (changed & WIPHY_PARAM_RETRY_LONG)
794 rdev->wiphy.retry_long = retry_long;
795 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
796 rdev->wiphy.frag_threshold = frag_threshold;
797 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
798 rdev->wiphy.rts_threshold = rts_threshold;
800 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
801 if (result) {
802 rdev->wiphy.retry_short = old_retry_short;
803 rdev->wiphy.retry_long = old_retry_long;
804 rdev->wiphy.frag_threshold = old_frag_threshold;
805 rdev->wiphy.rts_threshold = old_rts_threshold;
809 bad_res:
810 mutex_unlock(&rdev->mtx);
811 unlock:
812 rtnl_unlock();
813 return result;
817 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
818 struct cfg80211_registered_device *rdev,
819 struct net_device *dev)
821 void *hdr;
823 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
824 if (!hdr)
825 return -1;
827 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
828 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
829 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
830 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
832 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
833 rdev->devlist_generation ^
834 (cfg80211_rdev_list_generation << 2));
836 return genlmsg_end(msg, hdr);
838 nla_put_failure:
839 genlmsg_cancel(msg, hdr);
840 return -EMSGSIZE;
843 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
845 int wp_idx = 0;
846 int if_idx = 0;
847 int wp_start = cb->args[0];
848 int if_start = cb->args[1];
849 struct cfg80211_registered_device *rdev;
850 struct wireless_dev *wdev;
852 mutex_lock(&cfg80211_mutex);
853 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
854 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
855 continue;
856 if (wp_idx < wp_start) {
857 wp_idx++;
858 continue;
860 if_idx = 0;
862 mutex_lock(&rdev->devlist_mtx);
863 list_for_each_entry(wdev, &rdev->netdev_list, list) {
864 if (if_idx < if_start) {
865 if_idx++;
866 continue;
868 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
869 cb->nlh->nlmsg_seq, NLM_F_MULTI,
870 rdev, wdev->netdev) < 0) {
871 mutex_unlock(&rdev->devlist_mtx);
872 goto out;
874 if_idx++;
876 mutex_unlock(&rdev->devlist_mtx);
878 wp_idx++;
880 out:
881 mutex_unlock(&cfg80211_mutex);
883 cb->args[0] = wp_idx;
884 cb->args[1] = if_idx;
886 return skb->len;
889 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
891 struct sk_buff *msg;
892 struct cfg80211_registered_device *dev;
893 struct net_device *netdev;
894 int err;
896 err = get_rdev_dev_by_info_ifindex(info, &dev, &netdev);
897 if (err)
898 return err;
900 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
901 if (!msg)
902 goto out_err;
904 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
905 dev, netdev) < 0)
906 goto out_free;
908 dev_put(netdev);
909 cfg80211_unlock_rdev(dev);
911 return genlmsg_reply(msg, info);
913 out_free:
914 nlmsg_free(msg);
915 out_err:
916 dev_put(netdev);
917 cfg80211_unlock_rdev(dev);
918 return -ENOBUFS;
921 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
922 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
923 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
924 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
925 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
926 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
929 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
931 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
932 int flag;
934 *mntrflags = 0;
936 if (!nla)
937 return -EINVAL;
939 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
940 nla, mntr_flags_policy))
941 return -EINVAL;
943 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
944 if (flags[flag])
945 *mntrflags |= (1<<flag);
947 return 0;
950 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
952 struct cfg80211_registered_device *rdev;
953 struct vif_params params;
954 int err;
955 enum nl80211_iftype otype, ntype;
956 struct net_device *dev;
957 u32 _flags, *flags = NULL;
958 bool change = false;
960 memset(&params, 0, sizeof(params));
962 rtnl_lock();
964 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
965 if (err)
966 goto unlock_rtnl;
968 otype = ntype = dev->ieee80211_ptr->iftype;
970 if (info->attrs[NL80211_ATTR_IFTYPE]) {
971 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
972 if (otype != ntype)
973 change = true;
974 if (ntype > NL80211_IFTYPE_MAX) {
975 err = -EINVAL;
976 goto unlock;
980 if (info->attrs[NL80211_ATTR_MESH_ID]) {
981 if (ntype != NL80211_IFTYPE_MESH_POINT) {
982 err = -EINVAL;
983 goto unlock;
985 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
986 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
987 change = true;
990 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
991 if (ntype != NL80211_IFTYPE_MONITOR) {
992 err = -EINVAL;
993 goto unlock;
995 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
996 &_flags);
997 if (err)
998 goto unlock;
1000 flags = &_flags;
1001 change = true;
1004 if (change)
1005 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
1006 else
1007 err = 0;
1009 unlock:
1010 dev_put(dev);
1011 cfg80211_unlock_rdev(rdev);
1012 unlock_rtnl:
1013 rtnl_unlock();
1014 return err;
1017 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1019 struct cfg80211_registered_device *rdev;
1020 struct vif_params params;
1021 int err;
1022 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
1023 u32 flags;
1025 memset(&params, 0, sizeof(params));
1027 if (!info->attrs[NL80211_ATTR_IFNAME])
1028 return -EINVAL;
1030 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1031 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1032 if (type > NL80211_IFTYPE_MAX)
1033 return -EINVAL;
1036 rtnl_lock();
1038 rdev = cfg80211_get_dev_from_info(info);
1039 if (IS_ERR(rdev)) {
1040 err = PTR_ERR(rdev);
1041 goto unlock_rtnl;
1044 if (!rdev->ops->add_virtual_intf ||
1045 !(rdev->wiphy.interface_modes & (1 << type))) {
1046 err = -EOPNOTSUPP;
1047 goto unlock;
1050 if (type == NL80211_IFTYPE_MESH_POINT &&
1051 info->attrs[NL80211_ATTR_MESH_ID]) {
1052 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1053 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1056 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1057 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1058 &flags);
1059 err = rdev->ops->add_virtual_intf(&rdev->wiphy,
1060 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
1061 type, err ? NULL : &flags, &params);
1063 unlock:
1064 cfg80211_unlock_rdev(rdev);
1065 unlock_rtnl:
1066 rtnl_unlock();
1067 return err;
1070 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1072 struct cfg80211_registered_device *rdev;
1073 int err;
1074 struct net_device *dev;
1076 rtnl_lock();
1078 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1079 if (err)
1080 goto unlock_rtnl;
1082 if (!rdev->ops->del_virtual_intf) {
1083 err = -EOPNOTSUPP;
1084 goto out;
1087 err = rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
1089 out:
1090 cfg80211_unlock_rdev(rdev);
1091 dev_put(dev);
1092 unlock_rtnl:
1093 rtnl_unlock();
1094 return err;
1097 struct get_key_cookie {
1098 struct sk_buff *msg;
1099 int error;
1100 int idx;
1103 static void get_key_callback(void *c, struct key_params *params)
1105 struct nlattr *key;
1106 struct get_key_cookie *cookie = c;
1108 if (params->key)
1109 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1110 params->key_len, params->key);
1112 if (params->seq)
1113 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1114 params->seq_len, params->seq);
1116 if (params->cipher)
1117 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1118 params->cipher);
1120 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1121 if (!key)
1122 goto nla_put_failure;
1124 if (params->key)
1125 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1126 params->key_len, params->key);
1128 if (params->seq)
1129 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1130 params->seq_len, params->seq);
1132 if (params->cipher)
1133 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1134 params->cipher);
1136 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1138 nla_nest_end(cookie->msg, key);
1140 return;
1141 nla_put_failure:
1142 cookie->error = 1;
1145 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1147 struct cfg80211_registered_device *rdev;
1148 int err;
1149 struct net_device *dev;
1150 u8 key_idx = 0;
1151 u8 *mac_addr = NULL;
1152 struct get_key_cookie cookie = {
1153 .error = 0,
1155 void *hdr;
1156 struct sk_buff *msg;
1158 if (info->attrs[NL80211_ATTR_KEY_IDX])
1159 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1161 if (key_idx > 5)
1162 return -EINVAL;
1164 if (info->attrs[NL80211_ATTR_MAC])
1165 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1167 rtnl_lock();
1169 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1170 if (err)
1171 goto unlock_rtnl;
1173 if (!rdev->ops->get_key) {
1174 err = -EOPNOTSUPP;
1175 goto out;
1178 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1179 if (!msg) {
1180 err = -ENOMEM;
1181 goto out;
1184 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1185 NL80211_CMD_NEW_KEY);
1187 if (IS_ERR(hdr)) {
1188 err = PTR_ERR(hdr);
1189 goto free_msg;
1192 cookie.msg = msg;
1193 cookie.idx = key_idx;
1195 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1196 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1197 if (mac_addr)
1198 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1200 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
1201 &cookie, get_key_callback);
1203 if (err)
1204 goto free_msg;
1206 if (cookie.error)
1207 goto nla_put_failure;
1209 genlmsg_end(msg, hdr);
1210 err = genlmsg_reply(msg, info);
1211 goto out;
1213 nla_put_failure:
1214 err = -ENOBUFS;
1215 free_msg:
1216 nlmsg_free(msg);
1217 out:
1218 cfg80211_unlock_rdev(rdev);
1219 dev_put(dev);
1220 unlock_rtnl:
1221 rtnl_unlock();
1223 return err;
1226 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1228 struct cfg80211_registered_device *rdev;
1229 struct key_parse key;
1230 int err;
1231 struct net_device *dev;
1232 int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1233 u8 key_index);
1235 err = nl80211_parse_key(info, &key);
1236 if (err)
1237 return err;
1239 if (key.idx < 0)
1240 return -EINVAL;
1242 /* only support setting default key */
1243 if (!key.def && !key.defmgmt)
1244 return -EINVAL;
1246 rtnl_lock();
1248 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1249 if (err)
1250 goto unlock_rtnl;
1252 if (key.def)
1253 func = rdev->ops->set_default_key;
1254 else
1255 func = rdev->ops->set_default_mgmt_key;
1257 if (!func) {
1258 err = -EOPNOTSUPP;
1259 goto out;
1262 wdev_lock(dev->ieee80211_ptr);
1263 err = nl80211_key_allowed(dev->ieee80211_ptr);
1264 if (!err)
1265 err = func(&rdev->wiphy, dev, key.idx);
1267 #ifdef CONFIG_WIRELESS_EXT
1268 if (!err) {
1269 if (func == rdev->ops->set_default_key)
1270 dev->ieee80211_ptr->wext.default_key = key.idx;
1271 else
1272 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
1274 #endif
1275 wdev_unlock(dev->ieee80211_ptr);
1277 out:
1278 cfg80211_unlock_rdev(rdev);
1279 dev_put(dev);
1281 unlock_rtnl:
1282 rtnl_unlock();
1284 return err;
1287 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1289 struct cfg80211_registered_device *rdev;
1290 int err;
1291 struct net_device *dev;
1292 struct key_parse key;
1293 u8 *mac_addr = NULL;
1295 err = nl80211_parse_key(info, &key);
1296 if (err)
1297 return err;
1299 if (!key.p.key)
1300 return -EINVAL;
1302 if (info->attrs[NL80211_ATTR_MAC])
1303 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1305 rtnl_lock();
1307 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1308 if (err)
1309 goto unlock_rtnl;
1311 if (!rdev->ops->add_key) {
1312 err = -EOPNOTSUPP;
1313 goto out;
1316 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
1317 err = -EINVAL;
1318 goto out;
1321 wdev_lock(dev->ieee80211_ptr);
1322 err = nl80211_key_allowed(dev->ieee80211_ptr);
1323 if (!err)
1324 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1325 mac_addr, &key.p);
1326 wdev_unlock(dev->ieee80211_ptr);
1328 out:
1329 cfg80211_unlock_rdev(rdev);
1330 dev_put(dev);
1331 unlock_rtnl:
1332 rtnl_unlock();
1334 return err;
1337 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1339 struct cfg80211_registered_device *rdev;
1340 int err;
1341 struct net_device *dev;
1342 u8 *mac_addr = NULL;
1343 struct key_parse key;
1345 err = nl80211_parse_key(info, &key);
1346 if (err)
1347 return err;
1349 if (info->attrs[NL80211_ATTR_MAC])
1350 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1352 rtnl_lock();
1354 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1355 if (err)
1356 goto unlock_rtnl;
1358 if (!rdev->ops->del_key) {
1359 err = -EOPNOTSUPP;
1360 goto out;
1363 wdev_lock(dev->ieee80211_ptr);
1364 err = nl80211_key_allowed(dev->ieee80211_ptr);
1365 if (!err)
1366 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
1368 #ifdef CONFIG_WIRELESS_EXT
1369 if (!err) {
1370 if (key.idx == dev->ieee80211_ptr->wext.default_key)
1371 dev->ieee80211_ptr->wext.default_key = -1;
1372 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
1373 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1375 #endif
1376 wdev_unlock(dev->ieee80211_ptr);
1378 out:
1379 cfg80211_unlock_rdev(rdev);
1380 dev_put(dev);
1382 unlock_rtnl:
1383 rtnl_unlock();
1385 return err;
1388 static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1390 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1391 struct beacon_parameters *info);
1392 struct cfg80211_registered_device *rdev;
1393 int err;
1394 struct net_device *dev;
1395 struct beacon_parameters params;
1396 int haveinfo = 0;
1398 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1399 return -EINVAL;
1401 rtnl_lock();
1403 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1404 if (err)
1405 goto unlock_rtnl;
1407 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1408 err = -EOPNOTSUPP;
1409 goto out;
1412 switch (info->genlhdr->cmd) {
1413 case NL80211_CMD_NEW_BEACON:
1414 /* these are required for NEW_BEACON */
1415 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1416 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1417 !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1418 err = -EINVAL;
1419 goto out;
1422 call = rdev->ops->add_beacon;
1423 break;
1424 case NL80211_CMD_SET_BEACON:
1425 call = rdev->ops->set_beacon;
1426 break;
1427 default:
1428 WARN_ON(1);
1429 err = -EOPNOTSUPP;
1430 goto out;
1433 if (!call) {
1434 err = -EOPNOTSUPP;
1435 goto out;
1438 memset(&params, 0, sizeof(params));
1440 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1441 params.interval =
1442 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1443 haveinfo = 1;
1446 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1447 params.dtim_period =
1448 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1449 haveinfo = 1;
1452 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1453 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1454 params.head_len =
1455 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1456 haveinfo = 1;
1459 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1460 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1461 params.tail_len =
1462 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1463 haveinfo = 1;
1466 if (!haveinfo) {
1467 err = -EINVAL;
1468 goto out;
1471 err = call(&rdev->wiphy, dev, &params);
1473 out:
1474 cfg80211_unlock_rdev(rdev);
1475 dev_put(dev);
1476 unlock_rtnl:
1477 rtnl_unlock();
1479 return err;
1482 static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1484 struct cfg80211_registered_device *rdev;
1485 int err;
1486 struct net_device *dev;
1488 rtnl_lock();
1490 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1491 if (err)
1492 goto unlock_rtnl;
1494 if (!rdev->ops->del_beacon) {
1495 err = -EOPNOTSUPP;
1496 goto out;
1499 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1500 err = -EOPNOTSUPP;
1501 goto out;
1503 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
1505 out:
1506 cfg80211_unlock_rdev(rdev);
1507 dev_put(dev);
1508 unlock_rtnl:
1509 rtnl_unlock();
1511 return err;
1514 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1515 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1516 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1517 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
1518 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
1521 static int parse_station_flags(struct genl_info *info,
1522 struct station_parameters *params)
1524 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
1525 struct nlattr *nla;
1526 int flag;
1529 * Try parsing the new attribute first so userspace
1530 * can specify both for older kernels.
1532 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1533 if (nla) {
1534 struct nl80211_sta_flag_update *sta_flags;
1536 sta_flags = nla_data(nla);
1537 params->sta_flags_mask = sta_flags->mask;
1538 params->sta_flags_set = sta_flags->set;
1539 if ((params->sta_flags_mask |
1540 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1541 return -EINVAL;
1542 return 0;
1545 /* if present, parse the old attribute */
1547 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
1548 if (!nla)
1549 return 0;
1551 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1552 nla, sta_flags_policy))
1553 return -EINVAL;
1555 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1556 params->sta_flags_mask &= ~1;
1558 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1559 if (flags[flag])
1560 params->sta_flags_set |= (1<<flag);
1562 return 0;
1565 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1566 int flags, struct net_device *dev,
1567 u8 *mac_addr, struct station_info *sinfo)
1569 void *hdr;
1570 struct nlattr *sinfoattr, *txrate;
1571 u16 bitrate;
1573 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1574 if (!hdr)
1575 return -1;
1577 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1578 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1580 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1582 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1583 if (!sinfoattr)
1584 goto nla_put_failure;
1585 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1586 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1587 sinfo->inactive_time);
1588 if (sinfo->filled & STATION_INFO_RX_BYTES)
1589 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1590 sinfo->rx_bytes);
1591 if (sinfo->filled & STATION_INFO_TX_BYTES)
1592 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1593 sinfo->tx_bytes);
1594 if (sinfo->filled & STATION_INFO_LLID)
1595 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1596 sinfo->llid);
1597 if (sinfo->filled & STATION_INFO_PLID)
1598 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1599 sinfo->plid);
1600 if (sinfo->filled & STATION_INFO_PLINK_STATE)
1601 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1602 sinfo->plink_state);
1603 if (sinfo->filled & STATION_INFO_SIGNAL)
1604 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1605 sinfo->signal);
1606 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1607 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1608 if (!txrate)
1609 goto nla_put_failure;
1611 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
1612 bitrate = cfg80211_calculate_bitrate(&sinfo->txrate);
1613 if (bitrate > 0)
1614 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
1616 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1617 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1618 sinfo->txrate.mcs);
1619 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1620 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1621 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1622 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1624 nla_nest_end(msg, txrate);
1626 if (sinfo->filled & STATION_INFO_RX_PACKETS)
1627 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1628 sinfo->rx_packets);
1629 if (sinfo->filled & STATION_INFO_TX_PACKETS)
1630 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1631 sinfo->tx_packets);
1632 nla_nest_end(msg, sinfoattr);
1634 return genlmsg_end(msg, hdr);
1636 nla_put_failure:
1637 genlmsg_cancel(msg, hdr);
1638 return -EMSGSIZE;
1641 static int nl80211_dump_station(struct sk_buff *skb,
1642 struct netlink_callback *cb)
1644 struct station_info sinfo;
1645 struct cfg80211_registered_device *dev;
1646 struct net_device *netdev;
1647 u8 mac_addr[ETH_ALEN];
1648 int ifidx = cb->args[0];
1649 int sta_idx = cb->args[1];
1650 int err;
1652 if (!ifidx) {
1653 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1654 nl80211_fam.attrbuf, nl80211_fam.maxattr,
1655 nl80211_policy);
1656 if (err)
1657 return err;
1659 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1660 return -EINVAL;
1662 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1663 if (!ifidx)
1664 return -EINVAL;
1667 rtnl_lock();
1669 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
1670 if (!netdev) {
1671 err = -ENODEV;
1672 goto out_rtnl;
1675 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
1676 if (IS_ERR(dev)) {
1677 err = PTR_ERR(dev);
1678 goto out_rtnl;
1681 if (!dev->ops->dump_station) {
1682 err = -EOPNOTSUPP;
1683 goto out_err;
1686 while (1) {
1687 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1688 mac_addr, &sinfo);
1689 if (err == -ENOENT)
1690 break;
1691 if (err)
1692 goto out_err;
1694 if (nl80211_send_station(skb,
1695 NETLINK_CB(cb->skb).pid,
1696 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1697 netdev, mac_addr,
1698 &sinfo) < 0)
1699 goto out;
1701 sta_idx++;
1705 out:
1706 cb->args[1] = sta_idx;
1707 err = skb->len;
1708 out_err:
1709 cfg80211_unlock_rdev(dev);
1710 out_rtnl:
1711 rtnl_unlock();
1713 return err;
1716 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1718 struct cfg80211_registered_device *rdev;
1719 int err;
1720 struct net_device *dev;
1721 struct station_info sinfo;
1722 struct sk_buff *msg;
1723 u8 *mac_addr = NULL;
1725 memset(&sinfo, 0, sizeof(sinfo));
1727 if (!info->attrs[NL80211_ATTR_MAC])
1728 return -EINVAL;
1730 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1732 rtnl_lock();
1734 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1735 if (err)
1736 goto out_rtnl;
1738 if (!rdev->ops->get_station) {
1739 err = -EOPNOTSUPP;
1740 goto out;
1743 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
1744 if (err)
1745 goto out;
1747 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1748 if (!msg)
1749 goto out;
1751 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
1752 dev, mac_addr, &sinfo) < 0)
1753 goto out_free;
1755 err = genlmsg_reply(msg, info);
1756 goto out;
1758 out_free:
1759 nlmsg_free(msg);
1760 out:
1761 cfg80211_unlock_rdev(rdev);
1762 dev_put(dev);
1763 out_rtnl:
1764 rtnl_unlock();
1766 return err;
1770 * Get vlan interface making sure it is on the right wiphy.
1772 static int get_vlan(struct genl_info *info,
1773 struct cfg80211_registered_device *rdev,
1774 struct net_device **vlan)
1776 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
1777 *vlan = NULL;
1779 if (vlanattr) {
1780 *vlan = dev_get_by_index(genl_info_net(info),
1781 nla_get_u32(vlanattr));
1782 if (!*vlan)
1783 return -ENODEV;
1784 if (!(*vlan)->ieee80211_ptr)
1785 return -EINVAL;
1786 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1787 return -EINVAL;
1789 return 0;
1792 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1794 struct cfg80211_registered_device *rdev;
1795 int err;
1796 struct net_device *dev;
1797 struct station_parameters params;
1798 u8 *mac_addr = NULL;
1800 memset(&params, 0, sizeof(params));
1802 params.listen_interval = -1;
1804 if (info->attrs[NL80211_ATTR_STA_AID])
1805 return -EINVAL;
1807 if (!info->attrs[NL80211_ATTR_MAC])
1808 return -EINVAL;
1810 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1812 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1813 params.supported_rates =
1814 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1815 params.supported_rates_len =
1816 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1819 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1820 params.listen_interval =
1821 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1823 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1824 params.ht_capa =
1825 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1827 if (parse_station_flags(info, &params))
1828 return -EINVAL;
1830 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1831 params.plink_action =
1832 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1834 rtnl_lock();
1836 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1837 if (err)
1838 goto out_rtnl;
1840 err = get_vlan(info, rdev, &params.vlan);
1841 if (err)
1842 goto out;
1844 /* validate settings */
1845 err = 0;
1847 switch (dev->ieee80211_ptr->iftype) {
1848 case NL80211_IFTYPE_AP:
1849 case NL80211_IFTYPE_AP_VLAN:
1850 /* disallow mesh-specific things */
1851 if (params.plink_action)
1852 err = -EINVAL;
1853 break;
1854 case NL80211_IFTYPE_STATION:
1855 /* disallow everything but AUTHORIZED flag */
1856 if (params.plink_action)
1857 err = -EINVAL;
1858 if (params.vlan)
1859 err = -EINVAL;
1860 if (params.supported_rates)
1861 err = -EINVAL;
1862 if (params.ht_capa)
1863 err = -EINVAL;
1864 if (params.listen_interval >= 0)
1865 err = -EINVAL;
1866 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
1867 err = -EINVAL;
1868 break;
1869 case NL80211_IFTYPE_MESH_POINT:
1870 /* disallow things mesh doesn't support */
1871 if (params.vlan)
1872 err = -EINVAL;
1873 if (params.ht_capa)
1874 err = -EINVAL;
1875 if (params.listen_interval >= 0)
1876 err = -EINVAL;
1877 if (params.supported_rates)
1878 err = -EINVAL;
1879 if (params.sta_flags_mask)
1880 err = -EINVAL;
1881 break;
1882 default:
1883 err = -EINVAL;
1886 if (err)
1887 goto out;
1889 if (!rdev->ops->change_station) {
1890 err = -EOPNOTSUPP;
1891 goto out;
1894 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
1896 out:
1897 if (params.vlan)
1898 dev_put(params.vlan);
1899 cfg80211_unlock_rdev(rdev);
1900 dev_put(dev);
1901 out_rtnl:
1902 rtnl_unlock();
1904 return err;
1907 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
1909 struct cfg80211_registered_device *rdev;
1910 int err;
1911 struct net_device *dev;
1912 struct station_parameters params;
1913 u8 *mac_addr = NULL;
1915 memset(&params, 0, sizeof(params));
1917 if (!info->attrs[NL80211_ATTR_MAC])
1918 return -EINVAL;
1920 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1921 return -EINVAL;
1923 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
1924 return -EINVAL;
1926 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1927 params.supported_rates =
1928 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1929 params.supported_rates_len =
1930 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1931 params.listen_interval =
1932 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1934 if (info->attrs[NL80211_ATTR_STA_AID]) {
1935 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
1936 if (!params.aid || params.aid > IEEE80211_MAX_AID)
1937 return -EINVAL;
1940 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1941 params.ht_capa =
1942 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1944 if (parse_station_flags(info, &params))
1945 return -EINVAL;
1947 rtnl_lock();
1949 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1950 if (err)
1951 goto out_rtnl;
1953 err = get_vlan(info, rdev, &params.vlan);
1954 if (err)
1955 goto out;
1957 /* validate settings */
1958 err = 0;
1960 switch (dev->ieee80211_ptr->iftype) {
1961 case NL80211_IFTYPE_AP:
1962 case NL80211_IFTYPE_AP_VLAN:
1963 /* all ok but must have AID */
1964 if (!params.aid)
1965 err = -EINVAL;
1966 break;
1967 case NL80211_IFTYPE_MESH_POINT:
1968 /* disallow things mesh doesn't support */
1969 if (params.vlan)
1970 err = -EINVAL;
1971 if (params.aid)
1972 err = -EINVAL;
1973 if (params.ht_capa)
1974 err = -EINVAL;
1975 if (params.listen_interval >= 0)
1976 err = -EINVAL;
1977 if (params.supported_rates)
1978 err = -EINVAL;
1979 if (params.sta_flags_mask)
1980 err = -EINVAL;
1981 break;
1982 default:
1983 err = -EINVAL;
1986 if (err)
1987 goto out;
1989 if (!rdev->ops->add_station) {
1990 err = -EOPNOTSUPP;
1991 goto out;
1994 if (!netif_running(dev)) {
1995 err = -ENETDOWN;
1996 goto out;
1999 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
2001 out:
2002 if (params.vlan)
2003 dev_put(params.vlan);
2004 cfg80211_unlock_rdev(rdev);
2005 dev_put(dev);
2006 out_rtnl:
2007 rtnl_unlock();
2009 return err;
2012 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2014 struct cfg80211_registered_device *rdev;
2015 int err;
2016 struct net_device *dev;
2017 u8 *mac_addr = NULL;
2019 if (info->attrs[NL80211_ATTR_MAC])
2020 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2022 rtnl_lock();
2024 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2025 if (err)
2026 goto out_rtnl;
2028 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2029 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2030 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2031 err = -EINVAL;
2032 goto out;
2035 if (!rdev->ops->del_station) {
2036 err = -EOPNOTSUPP;
2037 goto out;
2040 err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
2042 out:
2043 cfg80211_unlock_rdev(rdev);
2044 dev_put(dev);
2045 out_rtnl:
2046 rtnl_unlock();
2048 return err;
2051 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2052 int flags, struct net_device *dev,
2053 u8 *dst, u8 *next_hop,
2054 struct mpath_info *pinfo)
2056 void *hdr;
2057 struct nlattr *pinfoattr;
2059 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2060 if (!hdr)
2061 return -1;
2063 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2064 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2065 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2067 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2069 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2070 if (!pinfoattr)
2071 goto nla_put_failure;
2072 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2073 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2074 pinfo->frame_qlen);
2075 if (pinfo->filled & MPATH_INFO_DSN)
2076 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DSN,
2077 pinfo->dsn);
2078 if (pinfo->filled & MPATH_INFO_METRIC)
2079 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2080 pinfo->metric);
2081 if (pinfo->filled & MPATH_INFO_EXPTIME)
2082 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2083 pinfo->exptime);
2084 if (pinfo->filled & MPATH_INFO_FLAGS)
2085 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2086 pinfo->flags);
2087 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2088 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2089 pinfo->discovery_timeout);
2090 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2091 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2092 pinfo->discovery_retries);
2094 nla_nest_end(msg, pinfoattr);
2096 return genlmsg_end(msg, hdr);
2098 nla_put_failure:
2099 genlmsg_cancel(msg, hdr);
2100 return -EMSGSIZE;
2103 static int nl80211_dump_mpath(struct sk_buff *skb,
2104 struct netlink_callback *cb)
2106 struct mpath_info pinfo;
2107 struct cfg80211_registered_device *dev;
2108 struct net_device *netdev;
2109 u8 dst[ETH_ALEN];
2110 u8 next_hop[ETH_ALEN];
2111 int ifidx = cb->args[0];
2112 int path_idx = cb->args[1];
2113 int err;
2115 if (!ifidx) {
2116 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
2117 nl80211_fam.attrbuf, nl80211_fam.maxattr,
2118 nl80211_policy);
2119 if (err)
2120 return err;
2122 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
2123 return -EINVAL;
2125 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
2126 if (!ifidx)
2127 return -EINVAL;
2130 rtnl_lock();
2132 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
2133 if (!netdev) {
2134 err = -ENODEV;
2135 goto out_rtnl;
2138 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
2139 if (IS_ERR(dev)) {
2140 err = PTR_ERR(dev);
2141 goto out_rtnl;
2144 if (!dev->ops->dump_mpath) {
2145 err = -EOPNOTSUPP;
2146 goto out_err;
2149 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2150 err = -EOPNOTSUPP;
2151 goto out_err;
2154 while (1) {
2155 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2156 dst, next_hop, &pinfo);
2157 if (err == -ENOENT)
2158 break;
2159 if (err)
2160 goto out_err;
2162 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2163 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2164 netdev, dst, next_hop,
2165 &pinfo) < 0)
2166 goto out;
2168 path_idx++;
2172 out:
2173 cb->args[1] = path_idx;
2174 err = skb->len;
2175 out_err:
2176 cfg80211_unlock_rdev(dev);
2177 out_rtnl:
2178 rtnl_unlock();
2180 return err;
2183 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2185 struct cfg80211_registered_device *rdev;
2186 int err;
2187 struct net_device *dev;
2188 struct mpath_info pinfo;
2189 struct sk_buff *msg;
2190 u8 *dst = NULL;
2191 u8 next_hop[ETH_ALEN];
2193 memset(&pinfo, 0, sizeof(pinfo));
2195 if (!info->attrs[NL80211_ATTR_MAC])
2196 return -EINVAL;
2198 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2200 rtnl_lock();
2202 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2203 if (err)
2204 goto out_rtnl;
2206 if (!rdev->ops->get_mpath) {
2207 err = -EOPNOTSUPP;
2208 goto out;
2211 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2212 err = -EOPNOTSUPP;
2213 goto out;
2216 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2217 if (err)
2218 goto out;
2220 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2221 if (!msg)
2222 goto out;
2224 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2225 dev, dst, next_hop, &pinfo) < 0)
2226 goto out_free;
2228 err = genlmsg_reply(msg, info);
2229 goto out;
2231 out_free:
2232 nlmsg_free(msg);
2233 out:
2234 cfg80211_unlock_rdev(rdev);
2235 dev_put(dev);
2236 out_rtnl:
2237 rtnl_unlock();
2239 return err;
2242 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2244 struct cfg80211_registered_device *rdev;
2245 int err;
2246 struct net_device *dev;
2247 u8 *dst = NULL;
2248 u8 *next_hop = NULL;
2250 if (!info->attrs[NL80211_ATTR_MAC])
2251 return -EINVAL;
2253 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2254 return -EINVAL;
2256 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2257 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2259 rtnl_lock();
2261 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2262 if (err)
2263 goto out_rtnl;
2265 if (!rdev->ops->change_mpath) {
2266 err = -EOPNOTSUPP;
2267 goto out;
2270 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2271 err = -EOPNOTSUPP;
2272 goto out;
2275 if (!netif_running(dev)) {
2276 err = -ENETDOWN;
2277 goto out;
2280 err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2282 out:
2283 cfg80211_unlock_rdev(rdev);
2284 dev_put(dev);
2285 out_rtnl:
2286 rtnl_unlock();
2288 return err;
2290 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2292 struct cfg80211_registered_device *rdev;
2293 int err;
2294 struct net_device *dev;
2295 u8 *dst = NULL;
2296 u8 *next_hop = NULL;
2298 if (!info->attrs[NL80211_ATTR_MAC])
2299 return -EINVAL;
2301 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2302 return -EINVAL;
2304 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2305 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2307 rtnl_lock();
2309 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2310 if (err)
2311 goto out_rtnl;
2313 if (!rdev->ops->add_mpath) {
2314 err = -EOPNOTSUPP;
2315 goto out;
2318 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2319 err = -EOPNOTSUPP;
2320 goto out;
2323 if (!netif_running(dev)) {
2324 err = -ENETDOWN;
2325 goto out;
2328 err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2330 out:
2331 cfg80211_unlock_rdev(rdev);
2332 dev_put(dev);
2333 out_rtnl:
2334 rtnl_unlock();
2336 return err;
2339 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2341 struct cfg80211_registered_device *rdev;
2342 int err;
2343 struct net_device *dev;
2344 u8 *dst = NULL;
2346 if (info->attrs[NL80211_ATTR_MAC])
2347 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2349 rtnl_lock();
2351 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2352 if (err)
2353 goto out_rtnl;
2355 if (!rdev->ops->del_mpath) {
2356 err = -EOPNOTSUPP;
2357 goto out;
2360 err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2362 out:
2363 cfg80211_unlock_rdev(rdev);
2364 dev_put(dev);
2365 out_rtnl:
2366 rtnl_unlock();
2368 return err;
2371 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2373 struct cfg80211_registered_device *rdev;
2374 int err;
2375 struct net_device *dev;
2376 struct bss_parameters params;
2378 memset(&params, 0, sizeof(params));
2379 /* default to not changing parameters */
2380 params.use_cts_prot = -1;
2381 params.use_short_preamble = -1;
2382 params.use_short_slot_time = -1;
2384 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2385 params.use_cts_prot =
2386 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2387 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2388 params.use_short_preamble =
2389 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2390 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2391 params.use_short_slot_time =
2392 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
2393 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2394 params.basic_rates =
2395 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2396 params.basic_rates_len =
2397 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2400 rtnl_lock();
2402 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2403 if (err)
2404 goto out_rtnl;
2406 if (!rdev->ops->change_bss) {
2407 err = -EOPNOTSUPP;
2408 goto out;
2411 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2412 err = -EOPNOTSUPP;
2413 goto out;
2416 err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
2418 out:
2419 cfg80211_unlock_rdev(rdev);
2420 dev_put(dev);
2421 out_rtnl:
2422 rtnl_unlock();
2424 return err;
2427 static const struct nla_policy
2428 reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2429 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2430 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2431 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2432 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2433 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2434 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2437 static int parse_reg_rule(struct nlattr *tb[],
2438 struct ieee80211_reg_rule *reg_rule)
2440 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2441 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2443 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2444 return -EINVAL;
2445 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2446 return -EINVAL;
2447 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2448 return -EINVAL;
2449 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2450 return -EINVAL;
2451 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2452 return -EINVAL;
2454 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2456 freq_range->start_freq_khz =
2457 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2458 freq_range->end_freq_khz =
2459 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2460 freq_range->max_bandwidth_khz =
2461 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2463 power_rule->max_eirp =
2464 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2466 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2467 power_rule->max_antenna_gain =
2468 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2470 return 0;
2473 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2475 int r;
2476 char *data = NULL;
2479 * You should only get this when cfg80211 hasn't yet initialized
2480 * completely when built-in to the kernel right between the time
2481 * window between nl80211_init() and regulatory_init(), if that is
2482 * even possible.
2484 mutex_lock(&cfg80211_mutex);
2485 if (unlikely(!cfg80211_regdomain)) {
2486 mutex_unlock(&cfg80211_mutex);
2487 return -EINPROGRESS;
2489 mutex_unlock(&cfg80211_mutex);
2491 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2492 return -EINVAL;
2494 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2496 #ifdef CONFIG_WIRELESS_OLD_REGULATORY
2497 /* We ignore world regdom requests with the old regdom setup */
2498 if (is_world_regdom(data))
2499 return -EINVAL;
2500 #endif
2502 r = regulatory_hint_user(data);
2504 return r;
2507 static int nl80211_get_mesh_params(struct sk_buff *skb,
2508 struct genl_info *info)
2510 struct cfg80211_registered_device *rdev;
2511 struct mesh_config cur_params;
2512 int err;
2513 struct net_device *dev;
2514 void *hdr;
2515 struct nlattr *pinfoattr;
2516 struct sk_buff *msg;
2518 rtnl_lock();
2520 /* Look up our device */
2521 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2522 if (err)
2523 goto out_rtnl;
2525 if (!rdev->ops->get_mesh_params) {
2526 err = -EOPNOTSUPP;
2527 goto out;
2530 /* Get the mesh params */
2531 err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
2532 if (err)
2533 goto out;
2535 /* Draw up a netlink message to send back */
2536 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2537 if (!msg) {
2538 err = -ENOBUFS;
2539 goto out;
2541 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2542 NL80211_CMD_GET_MESH_PARAMS);
2543 if (!hdr)
2544 goto nla_put_failure;
2545 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2546 if (!pinfoattr)
2547 goto nla_put_failure;
2548 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2549 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2550 cur_params.dot11MeshRetryTimeout);
2551 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2552 cur_params.dot11MeshConfirmTimeout);
2553 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2554 cur_params.dot11MeshHoldingTimeout);
2555 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2556 cur_params.dot11MeshMaxPeerLinks);
2557 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2558 cur_params.dot11MeshMaxRetries);
2559 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2560 cur_params.dot11MeshTTL);
2561 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2562 cur_params.auto_open_plinks);
2563 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2564 cur_params.dot11MeshHWMPmaxPREQretries);
2565 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2566 cur_params.path_refresh_time);
2567 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2568 cur_params.min_discovery_timeout);
2569 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2570 cur_params.dot11MeshHWMPactivePathTimeout);
2571 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2572 cur_params.dot11MeshHWMPpreqMinInterval);
2573 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2574 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2575 nla_nest_end(msg, pinfoattr);
2576 genlmsg_end(msg, hdr);
2577 err = genlmsg_reply(msg, info);
2578 goto out;
2580 nla_put_failure:
2581 genlmsg_cancel(msg, hdr);
2582 err = -EMSGSIZE;
2583 out:
2584 /* Cleanup */
2585 cfg80211_unlock_rdev(rdev);
2586 dev_put(dev);
2587 out_rtnl:
2588 rtnl_unlock();
2590 return err;
2593 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2594 do {\
2595 if (table[attr_num]) {\
2596 cfg.param = nla_fn(table[attr_num]); \
2597 mask |= (1 << (attr_num - 1)); \
2599 } while (0);\
2601 static struct nla_policy
2602 nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
2603 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2604 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2605 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2606 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2607 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2608 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2609 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2611 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2612 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2613 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2614 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2615 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2616 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2619 static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2621 int err;
2622 u32 mask;
2623 struct cfg80211_registered_device *rdev;
2624 struct net_device *dev;
2625 struct mesh_config cfg;
2626 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2627 struct nlattr *parent_attr;
2629 parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2630 if (!parent_attr)
2631 return -EINVAL;
2632 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2633 parent_attr, nl80211_meshconf_params_policy))
2634 return -EINVAL;
2636 rtnl_lock();
2638 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2639 if (err)
2640 goto out_rtnl;
2642 if (!rdev->ops->set_mesh_params) {
2643 err = -EOPNOTSUPP;
2644 goto out;
2647 /* This makes sure that there aren't more than 32 mesh config
2648 * parameters (otherwise our bitfield scheme would not work.) */
2649 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2651 /* Fill in the params struct */
2652 mask = 0;
2653 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2654 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2655 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2656 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2657 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2658 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2659 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2660 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2661 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2662 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2663 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2664 mask, NL80211_MESHCONF_TTL, nla_get_u8);
2665 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2666 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2667 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2668 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2669 nla_get_u8);
2670 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2671 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2672 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2673 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2674 nla_get_u16);
2675 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2676 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2677 nla_get_u32);
2678 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2679 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2680 nla_get_u16);
2681 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2682 dot11MeshHWMPnetDiameterTraversalTime,
2683 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2684 nla_get_u16);
2686 /* Apply changes */
2687 err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
2689 out:
2690 /* cleanup */
2691 cfg80211_unlock_rdev(rdev);
2692 dev_put(dev);
2693 out_rtnl:
2694 rtnl_unlock();
2696 return err;
2699 #undef FILL_IN_MESH_PARAM_IF_SET
2701 static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2703 struct sk_buff *msg;
2704 void *hdr = NULL;
2705 struct nlattr *nl_reg_rules;
2706 unsigned int i;
2707 int err = -EINVAL;
2709 mutex_lock(&cfg80211_mutex);
2711 if (!cfg80211_regdomain)
2712 goto out;
2714 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2715 if (!msg) {
2716 err = -ENOBUFS;
2717 goto out;
2720 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2721 NL80211_CMD_GET_REG);
2722 if (!hdr)
2723 goto nla_put_failure;
2725 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2726 cfg80211_regdomain->alpha2);
2728 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2729 if (!nl_reg_rules)
2730 goto nla_put_failure;
2732 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2733 struct nlattr *nl_reg_rule;
2734 const struct ieee80211_reg_rule *reg_rule;
2735 const struct ieee80211_freq_range *freq_range;
2736 const struct ieee80211_power_rule *power_rule;
2738 reg_rule = &cfg80211_regdomain->reg_rules[i];
2739 freq_range = &reg_rule->freq_range;
2740 power_rule = &reg_rule->power_rule;
2742 nl_reg_rule = nla_nest_start(msg, i);
2743 if (!nl_reg_rule)
2744 goto nla_put_failure;
2746 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2747 reg_rule->flags);
2748 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2749 freq_range->start_freq_khz);
2750 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2751 freq_range->end_freq_khz);
2752 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2753 freq_range->max_bandwidth_khz);
2754 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2755 power_rule->max_antenna_gain);
2756 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2757 power_rule->max_eirp);
2759 nla_nest_end(msg, nl_reg_rule);
2762 nla_nest_end(msg, nl_reg_rules);
2764 genlmsg_end(msg, hdr);
2765 err = genlmsg_reply(msg, info);
2766 goto out;
2768 nla_put_failure:
2769 genlmsg_cancel(msg, hdr);
2770 err = -EMSGSIZE;
2771 out:
2772 mutex_unlock(&cfg80211_mutex);
2773 return err;
2776 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2778 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2779 struct nlattr *nl_reg_rule;
2780 char *alpha2 = NULL;
2781 int rem_reg_rules = 0, r = 0;
2782 u32 num_rules = 0, rule_idx = 0, size_of_regd;
2783 struct ieee80211_regdomain *rd = NULL;
2785 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2786 return -EINVAL;
2788 if (!info->attrs[NL80211_ATTR_REG_RULES])
2789 return -EINVAL;
2791 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2793 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2794 rem_reg_rules) {
2795 num_rules++;
2796 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
2797 return -EINVAL;
2800 mutex_lock(&cfg80211_mutex);
2802 if (!reg_is_valid_request(alpha2)) {
2803 r = -EINVAL;
2804 goto bad_reg;
2807 size_of_regd = sizeof(struct ieee80211_regdomain) +
2808 (num_rules * sizeof(struct ieee80211_reg_rule));
2810 rd = kzalloc(size_of_regd, GFP_KERNEL);
2811 if (!rd) {
2812 r = -ENOMEM;
2813 goto bad_reg;
2816 rd->n_reg_rules = num_rules;
2817 rd->alpha2[0] = alpha2[0];
2818 rd->alpha2[1] = alpha2[1];
2820 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2821 rem_reg_rules) {
2822 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2823 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2824 reg_rule_policy);
2825 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2826 if (r)
2827 goto bad_reg;
2829 rule_idx++;
2831 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
2832 r = -EINVAL;
2833 goto bad_reg;
2837 BUG_ON(rule_idx != num_rules);
2839 r = set_regdom(rd);
2841 mutex_unlock(&cfg80211_mutex);
2843 return r;
2845 bad_reg:
2846 mutex_unlock(&cfg80211_mutex);
2847 kfree(rd);
2848 return r;
2851 static int validate_scan_freqs(struct nlattr *freqs)
2853 struct nlattr *attr1, *attr2;
2854 int n_channels = 0, tmp1, tmp2;
2856 nla_for_each_nested(attr1, freqs, tmp1) {
2857 n_channels++;
2859 * Some hardware has a limited channel list for
2860 * scanning, and it is pretty much nonsensical
2861 * to scan for a channel twice, so disallow that
2862 * and don't require drivers to check that the
2863 * channel list they get isn't longer than what
2864 * they can scan, as long as they can scan all
2865 * the channels they registered at once.
2867 nla_for_each_nested(attr2, freqs, tmp2)
2868 if (attr1 != attr2 &&
2869 nla_get_u32(attr1) == nla_get_u32(attr2))
2870 return 0;
2873 return n_channels;
2876 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2878 struct cfg80211_registered_device *rdev;
2879 struct net_device *dev;
2880 struct cfg80211_scan_request *request;
2881 struct cfg80211_ssid *ssid;
2882 struct ieee80211_channel *channel;
2883 struct nlattr *attr;
2884 struct wiphy *wiphy;
2885 int err, tmp, n_ssids = 0, n_channels, i;
2886 enum ieee80211_band band;
2887 size_t ie_len;
2889 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2890 return -EINVAL;
2892 rtnl_lock();
2894 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2895 if (err)
2896 goto out_rtnl;
2898 wiphy = &rdev->wiphy;
2900 if (!rdev->ops->scan) {
2901 err = -EOPNOTSUPP;
2902 goto out;
2905 if (!netif_running(dev)) {
2906 err = -ENETDOWN;
2907 goto out;
2910 if (rdev->scan_req) {
2911 err = -EBUSY;
2912 goto out;
2915 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2916 n_channels = validate_scan_freqs(
2917 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2918 if (!n_channels) {
2919 err = -EINVAL;
2920 goto out;
2922 } else {
2923 n_channels = 0;
2925 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
2926 if (wiphy->bands[band])
2927 n_channels += wiphy->bands[band]->n_channels;
2930 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
2931 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
2932 n_ssids++;
2934 if (n_ssids > wiphy->max_scan_ssids) {
2935 err = -EINVAL;
2936 goto out;
2939 if (info->attrs[NL80211_ATTR_IE])
2940 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2941 else
2942 ie_len = 0;
2944 if (ie_len > wiphy->max_scan_ie_len) {
2945 err = -EINVAL;
2946 goto out;
2949 request = kzalloc(sizeof(*request)
2950 + sizeof(*ssid) * n_ssids
2951 + sizeof(channel) * n_channels
2952 + ie_len, GFP_KERNEL);
2953 if (!request) {
2954 err = -ENOMEM;
2955 goto out;
2958 request->n_channels = n_channels;
2959 if (n_ssids)
2960 request->ssids = (void *)&request->channels[n_channels];
2961 request->n_ssids = n_ssids;
2962 if (ie_len) {
2963 if (request->ssids)
2964 request->ie = (void *)(request->ssids + n_ssids);
2965 else
2966 request->ie = (void *)(request->channels + n_channels);
2969 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2970 /* user specified, bail out if channel not found */
2971 request->n_channels = n_channels;
2972 i = 0;
2973 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
2974 request->channels[i] = ieee80211_get_channel(wiphy, nla_get_u32(attr));
2975 if (!request->channels[i]) {
2976 err = -EINVAL;
2977 goto out_free;
2979 i++;
2981 } else {
2982 /* all channels */
2983 i = 0;
2984 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
2985 int j;
2986 if (!wiphy->bands[band])
2987 continue;
2988 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
2989 request->channels[i] = &wiphy->bands[band]->channels[j];
2990 i++;
2995 i = 0;
2996 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
2997 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
2998 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2999 err = -EINVAL;
3000 goto out_free;
3002 request->ssids[i].ssid_len = nla_len(attr);
3003 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3004 i++;
3008 if (info->attrs[NL80211_ATTR_IE]) {
3009 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3010 memcpy((void *)request->ie,
3011 nla_data(info->attrs[NL80211_ATTR_IE]),
3012 request->ie_len);
3015 request->dev = dev;
3016 request->wiphy = &rdev->wiphy;
3018 rdev->scan_req = request;
3019 err = rdev->ops->scan(&rdev->wiphy, dev, request);
3021 if (!err) {
3022 nl80211_send_scan_start(rdev, dev);
3023 dev_hold(dev);
3026 out_free:
3027 if (err) {
3028 rdev->scan_req = NULL;
3029 kfree(request);
3031 out:
3032 cfg80211_unlock_rdev(rdev);
3033 dev_put(dev);
3034 out_rtnl:
3035 rtnl_unlock();
3037 return err;
3040 static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3041 struct cfg80211_registered_device *rdev,
3042 struct wireless_dev *wdev,
3043 struct cfg80211_internal_bss *intbss)
3045 struct cfg80211_bss *res = &intbss->pub;
3046 void *hdr;
3047 struct nlattr *bss;
3048 int i;
3050 ASSERT_WDEV_LOCK(wdev);
3052 hdr = nl80211hdr_put(msg, pid, seq, flags,
3053 NL80211_CMD_NEW_SCAN_RESULTS);
3054 if (!hdr)
3055 return -1;
3057 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
3058 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
3060 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3061 if (!bss)
3062 goto nla_put_failure;
3063 if (!is_zero_ether_addr(res->bssid))
3064 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3065 if (res->information_elements && res->len_information_elements)
3066 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3067 res->len_information_elements,
3068 res->information_elements);
3069 if (res->tsf)
3070 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3071 if (res->beacon_interval)
3072 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3073 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3074 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
3076 switch (rdev->wiphy.signal_type) {
3077 case CFG80211_SIGNAL_TYPE_MBM:
3078 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3079 break;
3080 case CFG80211_SIGNAL_TYPE_UNSPEC:
3081 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3082 break;
3083 default:
3084 break;
3087 switch (wdev->iftype) {
3088 case NL80211_IFTYPE_STATION:
3089 if (intbss == wdev->current_bss)
3090 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3091 NL80211_BSS_STATUS_ASSOCIATED);
3092 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3093 if (intbss != wdev->auth_bsses[i])
3094 continue;
3095 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3096 NL80211_BSS_STATUS_AUTHENTICATED);
3097 break;
3099 break;
3100 case NL80211_IFTYPE_ADHOC:
3101 if (intbss == wdev->current_bss)
3102 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3103 NL80211_BSS_STATUS_IBSS_JOINED);
3104 break;
3105 default:
3106 break;
3109 nla_nest_end(msg, bss);
3111 return genlmsg_end(msg, hdr);
3113 nla_put_failure:
3114 genlmsg_cancel(msg, hdr);
3115 return -EMSGSIZE;
3118 static int nl80211_dump_scan(struct sk_buff *skb,
3119 struct netlink_callback *cb)
3121 struct cfg80211_registered_device *rdev;
3122 struct net_device *dev;
3123 struct cfg80211_internal_bss *scan;
3124 struct wireless_dev *wdev;
3125 int ifidx = cb->args[0];
3126 int start = cb->args[1], idx = 0;
3127 int err;
3129 if (!ifidx) {
3130 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
3131 nl80211_fam.attrbuf, nl80211_fam.maxattr,
3132 nl80211_policy);
3133 if (err)
3134 return err;
3136 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
3137 return -EINVAL;
3139 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
3140 if (!ifidx)
3141 return -EINVAL;
3142 cb->args[0] = ifidx;
3145 dev = dev_get_by_index(sock_net(skb->sk), ifidx);
3146 if (!dev)
3147 return -ENODEV;
3149 rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3150 if (IS_ERR(rdev)) {
3151 err = PTR_ERR(rdev);
3152 goto out_put_netdev;
3155 wdev = dev->ieee80211_ptr;
3157 wdev_lock(wdev);
3158 spin_lock_bh(&rdev->bss_lock);
3159 cfg80211_bss_expire(rdev);
3161 list_for_each_entry(scan, &rdev->bss_list, list) {
3162 if (++idx <= start)
3163 continue;
3164 if (nl80211_send_bss(skb,
3165 NETLINK_CB(cb->skb).pid,
3166 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3167 rdev, wdev, scan) < 0) {
3168 idx--;
3169 goto out;
3173 out:
3174 spin_unlock_bh(&rdev->bss_lock);
3175 wdev_unlock(wdev);
3177 cb->args[1] = idx;
3178 err = skb->len;
3179 cfg80211_unlock_rdev(rdev);
3180 out_put_netdev:
3181 dev_put(dev);
3183 return err;
3186 static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3188 return auth_type <= NL80211_AUTHTYPE_MAX;
3191 static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3193 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3194 NL80211_WPA_VERSION_2));
3197 static bool nl80211_valid_akm_suite(u32 akm)
3199 return akm == WLAN_AKM_SUITE_8021X ||
3200 akm == WLAN_AKM_SUITE_PSK;
3203 static bool nl80211_valid_cipher_suite(u32 cipher)
3205 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3206 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3207 cipher == WLAN_CIPHER_SUITE_TKIP ||
3208 cipher == WLAN_CIPHER_SUITE_CCMP ||
3209 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
3213 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3215 struct cfg80211_registered_device *rdev;
3216 struct net_device *dev;
3217 struct ieee80211_channel *chan;
3218 const u8 *bssid, *ssid, *ie = NULL;
3219 int err, ssid_len, ie_len = 0;
3220 enum nl80211_auth_type auth_type;
3221 struct key_parse key;
3223 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3224 return -EINVAL;
3226 if (!info->attrs[NL80211_ATTR_MAC])
3227 return -EINVAL;
3229 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3230 return -EINVAL;
3232 if (!info->attrs[NL80211_ATTR_SSID])
3233 return -EINVAL;
3235 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3236 return -EINVAL;
3238 err = nl80211_parse_key(info, &key);
3239 if (err)
3240 return err;
3242 if (key.idx >= 0) {
3243 if (!key.p.key || !key.p.key_len)
3244 return -EINVAL;
3245 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3246 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3247 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3248 key.p.key_len != WLAN_KEY_LEN_WEP104))
3249 return -EINVAL;
3250 if (key.idx > 4)
3251 return -EINVAL;
3252 } else {
3253 key.p.key_len = 0;
3254 key.p.key = NULL;
3257 rtnl_lock();
3259 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3260 if (err)
3261 goto unlock_rtnl;
3263 if (!rdev->ops->auth) {
3264 err = -EOPNOTSUPP;
3265 goto out;
3268 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3269 err = -EOPNOTSUPP;
3270 goto out;
3273 if (!netif_running(dev)) {
3274 err = -ENETDOWN;
3275 goto out;
3278 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3279 chan = ieee80211_get_channel(&rdev->wiphy,
3280 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3281 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3282 err = -EINVAL;
3283 goto out;
3286 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3287 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3289 if (info->attrs[NL80211_ATTR_IE]) {
3290 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3291 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3294 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3295 if (!nl80211_valid_auth_type(auth_type)) {
3296 err = -EINVAL;
3297 goto out;
3300 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3301 ssid, ssid_len, ie, ie_len,
3302 key.p.key, key.p.key_len, key.idx);
3304 out:
3305 cfg80211_unlock_rdev(rdev);
3306 dev_put(dev);
3307 unlock_rtnl:
3308 rtnl_unlock();
3309 return err;
3312 static int nl80211_crypto_settings(struct genl_info *info,
3313 struct cfg80211_crypto_settings *settings,
3314 int cipher_limit)
3316 memset(settings, 0, sizeof(*settings));
3318 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3320 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3321 void *data;
3322 int len, i;
3324 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3325 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3326 settings->n_ciphers_pairwise = len / sizeof(u32);
3328 if (len % sizeof(u32))
3329 return -EINVAL;
3331 if (settings->n_ciphers_pairwise > cipher_limit)
3332 return -EINVAL;
3334 memcpy(settings->ciphers_pairwise, data, len);
3336 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3337 if (!nl80211_valid_cipher_suite(
3338 settings->ciphers_pairwise[i]))
3339 return -EINVAL;
3342 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3343 settings->cipher_group =
3344 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3345 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3346 return -EINVAL;
3349 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3350 settings->wpa_versions =
3351 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3352 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3353 return -EINVAL;
3356 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3357 void *data;
3358 int len, i;
3360 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3361 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3362 settings->n_akm_suites = len / sizeof(u32);
3364 if (len % sizeof(u32))
3365 return -EINVAL;
3367 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
3368 return -EINVAL;
3370 memcpy(settings->akm_suites, data, len);
3372 for (i = 0; i < settings->n_akm_suites; i++)
3373 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3374 return -EINVAL;
3377 return 0;
3380 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3382 struct cfg80211_registered_device *rdev;
3383 struct net_device *dev;
3384 struct cfg80211_crypto_settings crypto;
3385 struct ieee80211_channel *chan, *fixedchan;
3386 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
3387 int err, ssid_len, ie_len = 0;
3388 bool use_mfp = false;
3390 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3391 return -EINVAL;
3393 if (!info->attrs[NL80211_ATTR_MAC] ||
3394 !info->attrs[NL80211_ATTR_SSID] ||
3395 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
3396 return -EINVAL;
3398 rtnl_lock();
3400 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3401 if (err)
3402 goto unlock_rtnl;
3404 if (!rdev->ops->assoc) {
3405 err = -EOPNOTSUPP;
3406 goto out;
3409 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3410 err = -EOPNOTSUPP;
3411 goto out;
3414 if (!netif_running(dev)) {
3415 err = -ENETDOWN;
3416 goto out;
3419 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3421 chan = ieee80211_get_channel(&rdev->wiphy,
3422 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3423 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3424 err = -EINVAL;
3425 goto out;
3428 mutex_lock(&rdev->devlist_mtx);
3429 fixedchan = rdev_fixed_channel(rdev, NULL);
3430 if (fixedchan && chan != fixedchan) {
3431 err = -EBUSY;
3432 mutex_unlock(&rdev->devlist_mtx);
3433 goto out;
3435 mutex_unlock(&rdev->devlist_mtx);
3437 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3438 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3440 if (info->attrs[NL80211_ATTR_IE]) {
3441 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3442 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3445 if (info->attrs[NL80211_ATTR_USE_MFP]) {
3446 enum nl80211_mfp mfp =
3447 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
3448 if (mfp == NL80211_MFP_REQUIRED)
3449 use_mfp = true;
3450 else if (mfp != NL80211_MFP_NO) {
3451 err = -EINVAL;
3452 goto out;
3456 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3457 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3459 err = nl80211_crypto_settings(info, &crypto, 1);
3460 if (!err)
3461 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3462 ssid, ssid_len, ie, ie_len, use_mfp,
3463 &crypto);
3465 out:
3466 cfg80211_unlock_rdev(rdev);
3467 dev_put(dev);
3468 unlock_rtnl:
3469 rtnl_unlock();
3470 return err;
3473 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3475 struct cfg80211_registered_device *rdev;
3476 struct net_device *dev;
3477 const u8 *ie = NULL, *bssid;
3478 int err, ie_len = 0;
3479 u16 reason_code;
3481 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3482 return -EINVAL;
3484 if (!info->attrs[NL80211_ATTR_MAC])
3485 return -EINVAL;
3487 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3488 return -EINVAL;
3490 rtnl_lock();
3492 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3493 if (err)
3494 goto unlock_rtnl;
3496 if (!rdev->ops->deauth) {
3497 err = -EOPNOTSUPP;
3498 goto out;
3501 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3502 err = -EOPNOTSUPP;
3503 goto out;
3506 if (!netif_running(dev)) {
3507 err = -ENETDOWN;
3508 goto out;
3511 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3513 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3514 if (reason_code == 0) {
3515 /* Reason Code 0 is reserved */
3516 err = -EINVAL;
3517 goto out;
3520 if (info->attrs[NL80211_ATTR_IE]) {
3521 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3522 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3525 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code);
3527 out:
3528 cfg80211_unlock_rdev(rdev);
3529 dev_put(dev);
3530 unlock_rtnl:
3531 rtnl_unlock();
3532 return err;
3535 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3537 struct cfg80211_registered_device *rdev;
3538 struct net_device *dev;
3539 const u8 *ie = NULL, *bssid;
3540 int err, ie_len = 0;
3541 u16 reason_code;
3543 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3544 return -EINVAL;
3546 if (!info->attrs[NL80211_ATTR_MAC])
3547 return -EINVAL;
3549 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3550 return -EINVAL;
3552 rtnl_lock();
3554 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3555 if (err)
3556 goto unlock_rtnl;
3558 if (!rdev->ops->disassoc) {
3559 err = -EOPNOTSUPP;
3560 goto out;
3563 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3564 err = -EOPNOTSUPP;
3565 goto out;
3568 if (!netif_running(dev)) {
3569 err = -ENETDOWN;
3570 goto out;
3573 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3575 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3576 if (reason_code == 0) {
3577 /* Reason Code 0 is reserved */
3578 err = -EINVAL;
3579 goto out;
3582 if (info->attrs[NL80211_ATTR_IE]) {
3583 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3584 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3587 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code);
3589 out:
3590 cfg80211_unlock_rdev(rdev);
3591 dev_put(dev);
3592 unlock_rtnl:
3593 rtnl_unlock();
3594 return err;
3597 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3599 struct cfg80211_registered_device *rdev;
3600 struct net_device *dev;
3601 struct cfg80211_ibss_params ibss;
3602 struct wiphy *wiphy;
3603 struct cfg80211_cached_keys *connkeys = NULL;
3604 int err;
3606 memset(&ibss, 0, sizeof(ibss));
3608 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3609 return -EINVAL;
3611 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3612 !info->attrs[NL80211_ATTR_SSID] ||
3613 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3614 return -EINVAL;
3616 ibss.beacon_interval = 100;
3618 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3619 ibss.beacon_interval =
3620 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3621 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3622 return -EINVAL;
3625 rtnl_lock();
3627 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3628 if (err)
3629 goto unlock_rtnl;
3631 if (!rdev->ops->join_ibss) {
3632 err = -EOPNOTSUPP;
3633 goto out;
3636 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3637 err = -EOPNOTSUPP;
3638 goto out;
3641 if (!netif_running(dev)) {
3642 err = -ENETDOWN;
3643 goto out;
3646 wiphy = &rdev->wiphy;
3648 if (info->attrs[NL80211_ATTR_MAC])
3649 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3650 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3651 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3653 if (info->attrs[NL80211_ATTR_IE]) {
3654 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3655 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3658 ibss.channel = ieee80211_get_channel(wiphy,
3659 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3660 if (!ibss.channel ||
3661 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3662 ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
3663 err = -EINVAL;
3664 goto out;
3667 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
3668 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3670 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3671 connkeys = nl80211_parse_connkeys(rdev,
3672 info->attrs[NL80211_ATTR_KEYS]);
3673 if (IS_ERR(connkeys)) {
3674 err = PTR_ERR(connkeys);
3675 connkeys = NULL;
3676 goto out;
3680 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
3682 out:
3683 cfg80211_unlock_rdev(rdev);
3684 dev_put(dev);
3685 unlock_rtnl:
3686 if (err)
3687 kfree(connkeys);
3688 rtnl_unlock();
3689 return err;
3692 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3694 struct cfg80211_registered_device *rdev;
3695 struct net_device *dev;
3696 int err;
3698 rtnl_lock();
3700 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3701 if (err)
3702 goto unlock_rtnl;
3704 if (!rdev->ops->leave_ibss) {
3705 err = -EOPNOTSUPP;
3706 goto out;
3709 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3710 err = -EOPNOTSUPP;
3711 goto out;
3714 if (!netif_running(dev)) {
3715 err = -ENETDOWN;
3716 goto out;
3719 err = cfg80211_leave_ibss(rdev, dev, false);
3721 out:
3722 cfg80211_unlock_rdev(rdev);
3723 dev_put(dev);
3724 unlock_rtnl:
3725 rtnl_unlock();
3726 return err;
3729 #ifdef CONFIG_NL80211_TESTMODE
3730 static struct genl_multicast_group nl80211_testmode_mcgrp = {
3731 .name = "testmode",
3734 static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3736 struct cfg80211_registered_device *rdev;
3737 int err;
3739 if (!info->attrs[NL80211_ATTR_TESTDATA])
3740 return -EINVAL;
3742 rtnl_lock();
3744 rdev = cfg80211_get_dev_from_info(info);
3745 if (IS_ERR(rdev)) {
3746 err = PTR_ERR(rdev);
3747 goto unlock_rtnl;
3750 err = -EOPNOTSUPP;
3751 if (rdev->ops->testmode_cmd) {
3752 rdev->testmode_info = info;
3753 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3754 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
3755 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
3756 rdev->testmode_info = NULL;
3759 cfg80211_unlock_rdev(rdev);
3761 unlock_rtnl:
3762 rtnl_unlock();
3763 return err;
3766 static struct sk_buff *
3767 __cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
3768 int approxlen, u32 pid, u32 seq, gfp_t gfp)
3770 struct sk_buff *skb;
3771 void *hdr;
3772 struct nlattr *data;
3774 skb = nlmsg_new(approxlen + 100, gfp);
3775 if (!skb)
3776 return NULL;
3778 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
3779 if (!hdr) {
3780 kfree_skb(skb);
3781 return NULL;
3784 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3785 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
3787 ((void **)skb->cb)[0] = rdev;
3788 ((void **)skb->cb)[1] = hdr;
3789 ((void **)skb->cb)[2] = data;
3791 return skb;
3793 nla_put_failure:
3794 kfree_skb(skb);
3795 return NULL;
3798 struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
3799 int approxlen)
3801 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3803 if (WARN_ON(!rdev->testmode_info))
3804 return NULL;
3806 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
3807 rdev->testmode_info->snd_pid,
3808 rdev->testmode_info->snd_seq,
3809 GFP_KERNEL);
3811 EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
3813 int cfg80211_testmode_reply(struct sk_buff *skb)
3815 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
3816 void *hdr = ((void **)skb->cb)[1];
3817 struct nlattr *data = ((void **)skb->cb)[2];
3819 if (WARN_ON(!rdev->testmode_info)) {
3820 kfree_skb(skb);
3821 return -EINVAL;
3824 nla_nest_end(skb, data);
3825 genlmsg_end(skb, hdr);
3826 return genlmsg_reply(skb, rdev->testmode_info);
3828 EXPORT_SYMBOL(cfg80211_testmode_reply);
3830 struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
3831 int approxlen, gfp_t gfp)
3833 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3835 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
3837 EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
3839 void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
3841 void *hdr = ((void **)skb->cb)[1];
3842 struct nlattr *data = ((void **)skb->cb)[2];
3844 nla_nest_end(skb, data);
3845 genlmsg_end(skb, hdr);
3846 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
3848 EXPORT_SYMBOL(cfg80211_testmode_event);
3849 #endif
3851 static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
3853 struct cfg80211_registered_device *rdev;
3854 struct net_device *dev;
3855 struct cfg80211_connect_params connect;
3856 struct wiphy *wiphy;
3857 struct cfg80211_cached_keys *connkeys = NULL;
3858 int err;
3860 memset(&connect, 0, sizeof(connect));
3862 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3863 return -EINVAL;
3865 if (!info->attrs[NL80211_ATTR_SSID] ||
3866 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3867 return -EINVAL;
3869 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
3870 connect.auth_type =
3871 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3872 if (!nl80211_valid_auth_type(connect.auth_type))
3873 return -EINVAL;
3874 } else
3875 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
3877 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
3879 err = nl80211_crypto_settings(info, &connect.crypto,
3880 NL80211_MAX_NR_CIPHER_SUITES);
3881 if (err)
3882 return err;
3883 rtnl_lock();
3885 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3886 if (err)
3887 goto unlock_rtnl;
3889 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3890 err = -EOPNOTSUPP;
3891 goto out;
3894 if (!netif_running(dev)) {
3895 err = -ENETDOWN;
3896 goto out;
3899 wiphy = &rdev->wiphy;
3901 if (info->attrs[NL80211_ATTR_MAC])
3902 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3903 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3904 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3906 if (info->attrs[NL80211_ATTR_IE]) {
3907 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3908 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3911 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
3912 connect.channel =
3913 ieee80211_get_channel(wiphy,
3914 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3915 if (!connect.channel ||
3916 connect.channel->flags & IEEE80211_CHAN_DISABLED) {
3917 err = -EINVAL;
3918 goto out;
3922 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3923 connkeys = nl80211_parse_connkeys(rdev,
3924 info->attrs[NL80211_ATTR_KEYS]);
3925 if (IS_ERR(connkeys)) {
3926 err = PTR_ERR(connkeys);
3927 connkeys = NULL;
3928 goto out;
3932 err = cfg80211_connect(rdev, dev, &connect, connkeys);
3934 out:
3935 cfg80211_unlock_rdev(rdev);
3936 dev_put(dev);
3937 unlock_rtnl:
3938 if (err)
3939 kfree(connkeys);
3940 rtnl_unlock();
3941 return err;
3944 static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
3946 struct cfg80211_registered_device *rdev;
3947 struct net_device *dev;
3948 int err;
3949 u16 reason;
3951 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3952 reason = WLAN_REASON_DEAUTH_LEAVING;
3953 else
3954 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3956 if (reason == 0)
3957 return -EINVAL;
3959 rtnl_lock();
3961 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3962 if (err)
3963 goto unlock_rtnl;
3965 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3966 err = -EOPNOTSUPP;
3967 goto out;
3970 if (!netif_running(dev)) {
3971 err = -ENETDOWN;
3972 goto out;
3975 err = cfg80211_disconnect(rdev, dev, reason, true);
3977 out:
3978 cfg80211_unlock_rdev(rdev);
3979 dev_put(dev);
3980 unlock_rtnl:
3981 rtnl_unlock();
3982 return err;
3985 static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
3987 struct cfg80211_registered_device *rdev;
3988 struct net *net;
3989 int err;
3990 u32 pid;
3992 if (!info->attrs[NL80211_ATTR_PID])
3993 return -EINVAL;
3995 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
3997 rtnl_lock();
3999 rdev = cfg80211_get_dev_from_info(info);
4000 if (IS_ERR(rdev)) {
4001 err = PTR_ERR(rdev);
4002 goto out_rtnl;
4005 net = get_net_ns_by_pid(pid);
4006 if (IS_ERR(net)) {
4007 err = PTR_ERR(net);
4008 goto out;
4011 err = 0;
4013 /* check if anything to do */
4014 if (net_eq(wiphy_net(&rdev->wiphy), net))
4015 goto out_put_net;
4017 err = cfg80211_switch_netns(rdev, net);
4018 out_put_net:
4019 put_net(net);
4020 out:
4021 cfg80211_unlock_rdev(rdev);
4022 out_rtnl:
4023 rtnl_unlock();
4024 return err;
4027 static struct genl_ops nl80211_ops[] = {
4029 .cmd = NL80211_CMD_GET_WIPHY,
4030 .doit = nl80211_get_wiphy,
4031 .dumpit = nl80211_dump_wiphy,
4032 .policy = nl80211_policy,
4033 /* can be retrieved by unprivileged users */
4036 .cmd = NL80211_CMD_SET_WIPHY,
4037 .doit = nl80211_set_wiphy,
4038 .policy = nl80211_policy,
4039 .flags = GENL_ADMIN_PERM,
4042 .cmd = NL80211_CMD_GET_INTERFACE,
4043 .doit = nl80211_get_interface,
4044 .dumpit = nl80211_dump_interface,
4045 .policy = nl80211_policy,
4046 /* can be retrieved by unprivileged users */
4049 .cmd = NL80211_CMD_SET_INTERFACE,
4050 .doit = nl80211_set_interface,
4051 .policy = nl80211_policy,
4052 .flags = GENL_ADMIN_PERM,
4055 .cmd = NL80211_CMD_NEW_INTERFACE,
4056 .doit = nl80211_new_interface,
4057 .policy = nl80211_policy,
4058 .flags = GENL_ADMIN_PERM,
4061 .cmd = NL80211_CMD_DEL_INTERFACE,
4062 .doit = nl80211_del_interface,
4063 .policy = nl80211_policy,
4064 .flags = GENL_ADMIN_PERM,
4067 .cmd = NL80211_CMD_GET_KEY,
4068 .doit = nl80211_get_key,
4069 .policy = nl80211_policy,
4070 .flags = GENL_ADMIN_PERM,
4073 .cmd = NL80211_CMD_SET_KEY,
4074 .doit = nl80211_set_key,
4075 .policy = nl80211_policy,
4076 .flags = GENL_ADMIN_PERM,
4079 .cmd = NL80211_CMD_NEW_KEY,
4080 .doit = nl80211_new_key,
4081 .policy = nl80211_policy,
4082 .flags = GENL_ADMIN_PERM,
4085 .cmd = NL80211_CMD_DEL_KEY,
4086 .doit = nl80211_del_key,
4087 .policy = nl80211_policy,
4088 .flags = GENL_ADMIN_PERM,
4091 .cmd = NL80211_CMD_SET_BEACON,
4092 .policy = nl80211_policy,
4093 .flags = GENL_ADMIN_PERM,
4094 .doit = nl80211_addset_beacon,
4097 .cmd = NL80211_CMD_NEW_BEACON,
4098 .policy = nl80211_policy,
4099 .flags = GENL_ADMIN_PERM,
4100 .doit = nl80211_addset_beacon,
4103 .cmd = NL80211_CMD_DEL_BEACON,
4104 .policy = nl80211_policy,
4105 .flags = GENL_ADMIN_PERM,
4106 .doit = nl80211_del_beacon,
4109 .cmd = NL80211_CMD_GET_STATION,
4110 .doit = nl80211_get_station,
4111 .dumpit = nl80211_dump_station,
4112 .policy = nl80211_policy,
4115 .cmd = NL80211_CMD_SET_STATION,
4116 .doit = nl80211_set_station,
4117 .policy = nl80211_policy,
4118 .flags = GENL_ADMIN_PERM,
4121 .cmd = NL80211_CMD_NEW_STATION,
4122 .doit = nl80211_new_station,
4123 .policy = nl80211_policy,
4124 .flags = GENL_ADMIN_PERM,
4127 .cmd = NL80211_CMD_DEL_STATION,
4128 .doit = nl80211_del_station,
4129 .policy = nl80211_policy,
4130 .flags = GENL_ADMIN_PERM,
4133 .cmd = NL80211_CMD_GET_MPATH,
4134 .doit = nl80211_get_mpath,
4135 .dumpit = nl80211_dump_mpath,
4136 .policy = nl80211_policy,
4137 .flags = GENL_ADMIN_PERM,
4140 .cmd = NL80211_CMD_SET_MPATH,
4141 .doit = nl80211_set_mpath,
4142 .policy = nl80211_policy,
4143 .flags = GENL_ADMIN_PERM,
4146 .cmd = NL80211_CMD_NEW_MPATH,
4147 .doit = nl80211_new_mpath,
4148 .policy = nl80211_policy,
4149 .flags = GENL_ADMIN_PERM,
4152 .cmd = NL80211_CMD_DEL_MPATH,
4153 .doit = nl80211_del_mpath,
4154 .policy = nl80211_policy,
4155 .flags = GENL_ADMIN_PERM,
4158 .cmd = NL80211_CMD_SET_BSS,
4159 .doit = nl80211_set_bss,
4160 .policy = nl80211_policy,
4161 .flags = GENL_ADMIN_PERM,
4164 .cmd = NL80211_CMD_GET_REG,
4165 .doit = nl80211_get_reg,
4166 .policy = nl80211_policy,
4167 /* can be retrieved by unprivileged users */
4170 .cmd = NL80211_CMD_SET_REG,
4171 .doit = nl80211_set_reg,
4172 .policy = nl80211_policy,
4173 .flags = GENL_ADMIN_PERM,
4176 .cmd = NL80211_CMD_REQ_SET_REG,
4177 .doit = nl80211_req_set_reg,
4178 .policy = nl80211_policy,
4179 .flags = GENL_ADMIN_PERM,
4182 .cmd = NL80211_CMD_GET_MESH_PARAMS,
4183 .doit = nl80211_get_mesh_params,
4184 .policy = nl80211_policy,
4185 /* can be retrieved by unprivileged users */
4188 .cmd = NL80211_CMD_SET_MESH_PARAMS,
4189 .doit = nl80211_set_mesh_params,
4190 .policy = nl80211_policy,
4191 .flags = GENL_ADMIN_PERM,
4194 .cmd = NL80211_CMD_TRIGGER_SCAN,
4195 .doit = nl80211_trigger_scan,
4196 .policy = nl80211_policy,
4197 .flags = GENL_ADMIN_PERM,
4200 .cmd = NL80211_CMD_GET_SCAN,
4201 .policy = nl80211_policy,
4202 .dumpit = nl80211_dump_scan,
4205 .cmd = NL80211_CMD_AUTHENTICATE,
4206 .doit = nl80211_authenticate,
4207 .policy = nl80211_policy,
4208 .flags = GENL_ADMIN_PERM,
4211 .cmd = NL80211_CMD_ASSOCIATE,
4212 .doit = nl80211_associate,
4213 .policy = nl80211_policy,
4214 .flags = GENL_ADMIN_PERM,
4217 .cmd = NL80211_CMD_DEAUTHENTICATE,
4218 .doit = nl80211_deauthenticate,
4219 .policy = nl80211_policy,
4220 .flags = GENL_ADMIN_PERM,
4223 .cmd = NL80211_CMD_DISASSOCIATE,
4224 .doit = nl80211_disassociate,
4225 .policy = nl80211_policy,
4226 .flags = GENL_ADMIN_PERM,
4229 .cmd = NL80211_CMD_JOIN_IBSS,
4230 .doit = nl80211_join_ibss,
4231 .policy = nl80211_policy,
4232 .flags = GENL_ADMIN_PERM,
4235 .cmd = NL80211_CMD_LEAVE_IBSS,
4236 .doit = nl80211_leave_ibss,
4237 .policy = nl80211_policy,
4238 .flags = GENL_ADMIN_PERM,
4240 #ifdef CONFIG_NL80211_TESTMODE
4242 .cmd = NL80211_CMD_TESTMODE,
4243 .doit = nl80211_testmode_do,
4244 .policy = nl80211_policy,
4245 .flags = GENL_ADMIN_PERM,
4247 #endif
4249 .cmd = NL80211_CMD_CONNECT,
4250 .doit = nl80211_connect,
4251 .policy = nl80211_policy,
4252 .flags = GENL_ADMIN_PERM,
4255 .cmd = NL80211_CMD_DISCONNECT,
4256 .doit = nl80211_disconnect,
4257 .policy = nl80211_policy,
4258 .flags = GENL_ADMIN_PERM,
4261 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
4262 .doit = nl80211_wiphy_netns,
4263 .policy = nl80211_policy,
4264 .flags = GENL_ADMIN_PERM,
4267 static struct genl_multicast_group nl80211_mlme_mcgrp = {
4268 .name = "mlme",
4271 /* multicast groups */
4272 static struct genl_multicast_group nl80211_config_mcgrp = {
4273 .name = "config",
4275 static struct genl_multicast_group nl80211_scan_mcgrp = {
4276 .name = "scan",
4278 static struct genl_multicast_group nl80211_regulatory_mcgrp = {
4279 .name = "regulatory",
4282 /* notification functions */
4284 void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
4286 struct sk_buff *msg;
4288 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4289 if (!msg)
4290 return;
4292 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
4293 nlmsg_free(msg);
4294 return;
4297 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4298 nl80211_config_mcgrp.id, GFP_KERNEL);
4301 static int nl80211_add_scan_req(struct sk_buff *msg,
4302 struct cfg80211_registered_device *rdev)
4304 struct cfg80211_scan_request *req = rdev->scan_req;
4305 struct nlattr *nest;
4306 int i;
4308 ASSERT_RDEV_LOCK(rdev);
4310 if (WARN_ON(!req))
4311 return 0;
4313 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
4314 if (!nest)
4315 goto nla_put_failure;
4316 for (i = 0; i < req->n_ssids; i++)
4317 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
4318 nla_nest_end(msg, nest);
4320 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
4321 if (!nest)
4322 goto nla_put_failure;
4323 for (i = 0; i < req->n_channels; i++)
4324 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
4325 nla_nest_end(msg, nest);
4327 if (req->ie)
4328 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
4330 return 0;
4331 nla_put_failure:
4332 return -ENOBUFS;
4335 static int nl80211_send_scan_msg(struct sk_buff *msg,
4336 struct cfg80211_registered_device *rdev,
4337 struct net_device *netdev,
4338 u32 pid, u32 seq, int flags,
4339 u32 cmd)
4341 void *hdr;
4343 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
4344 if (!hdr)
4345 return -1;
4347 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4348 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4350 /* ignore errors and send incomplete event anyway */
4351 nl80211_add_scan_req(msg, rdev);
4353 return genlmsg_end(msg, hdr);
4355 nla_put_failure:
4356 genlmsg_cancel(msg, hdr);
4357 return -EMSGSIZE;
4360 void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
4361 struct net_device *netdev)
4363 struct sk_buff *msg;
4365 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4366 if (!msg)
4367 return;
4369 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4370 NL80211_CMD_TRIGGER_SCAN) < 0) {
4371 nlmsg_free(msg);
4372 return;
4375 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4376 nl80211_scan_mcgrp.id, GFP_KERNEL);
4379 void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
4380 struct net_device *netdev)
4382 struct sk_buff *msg;
4384 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4385 if (!msg)
4386 return;
4388 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4389 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
4390 nlmsg_free(msg);
4391 return;
4394 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4395 nl80211_scan_mcgrp.id, GFP_KERNEL);
4398 void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
4399 struct net_device *netdev)
4401 struct sk_buff *msg;
4403 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4404 if (!msg)
4405 return;
4407 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4408 NL80211_CMD_SCAN_ABORTED) < 0) {
4409 nlmsg_free(msg);
4410 return;
4413 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4414 nl80211_scan_mcgrp.id, GFP_KERNEL);
4418 * This can happen on global regulatory changes or device specific settings
4419 * based on custom world regulatory domains.
4421 void nl80211_send_reg_change_event(struct regulatory_request *request)
4423 struct sk_buff *msg;
4424 void *hdr;
4426 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4427 if (!msg)
4428 return;
4430 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
4431 if (!hdr) {
4432 nlmsg_free(msg);
4433 return;
4436 /* Userspace can always count this one always being set */
4437 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
4439 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
4440 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4441 NL80211_REGDOM_TYPE_WORLD);
4442 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
4443 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4444 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
4445 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
4446 request->intersect)
4447 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4448 NL80211_REGDOM_TYPE_INTERSECTION);
4449 else {
4450 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4451 NL80211_REGDOM_TYPE_COUNTRY);
4452 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
4455 if (wiphy_idx_valid(request->wiphy_idx))
4456 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
4458 if (genlmsg_end(msg, hdr) < 0) {
4459 nlmsg_free(msg);
4460 return;
4463 rcu_read_lock();
4464 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
4465 GFP_ATOMIC);
4466 rcu_read_unlock();
4468 return;
4470 nla_put_failure:
4471 genlmsg_cancel(msg, hdr);
4472 nlmsg_free(msg);
4475 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
4476 struct net_device *netdev,
4477 const u8 *buf, size_t len,
4478 enum nl80211_commands cmd, gfp_t gfp)
4480 struct sk_buff *msg;
4481 void *hdr;
4483 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4484 if (!msg)
4485 return;
4487 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4488 if (!hdr) {
4489 nlmsg_free(msg);
4490 return;
4493 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4494 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4495 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
4497 if (genlmsg_end(msg, hdr) < 0) {
4498 nlmsg_free(msg);
4499 return;
4502 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4503 nl80211_mlme_mcgrp.id, gfp);
4504 return;
4506 nla_put_failure:
4507 genlmsg_cancel(msg, hdr);
4508 nlmsg_free(msg);
4511 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
4512 struct net_device *netdev, const u8 *buf,
4513 size_t len, gfp_t gfp)
4515 nl80211_send_mlme_event(rdev, netdev, buf, len,
4516 NL80211_CMD_AUTHENTICATE, gfp);
4519 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
4520 struct net_device *netdev, const u8 *buf,
4521 size_t len, gfp_t gfp)
4523 nl80211_send_mlme_event(rdev, netdev, buf, len,
4524 NL80211_CMD_ASSOCIATE, gfp);
4527 void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
4528 struct net_device *netdev, const u8 *buf,
4529 size_t len, gfp_t gfp)
4531 nl80211_send_mlme_event(rdev, netdev, buf, len,
4532 NL80211_CMD_DEAUTHENTICATE, gfp);
4535 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
4536 struct net_device *netdev, const u8 *buf,
4537 size_t len, gfp_t gfp)
4539 nl80211_send_mlme_event(rdev, netdev, buf, len,
4540 NL80211_CMD_DISASSOCIATE, gfp);
4543 static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
4544 struct net_device *netdev, int cmd,
4545 const u8 *addr, gfp_t gfp)
4547 struct sk_buff *msg;
4548 void *hdr;
4550 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4551 if (!msg)
4552 return;
4554 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4555 if (!hdr) {
4556 nlmsg_free(msg);
4557 return;
4560 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4561 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4562 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
4563 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4565 if (genlmsg_end(msg, hdr) < 0) {
4566 nlmsg_free(msg);
4567 return;
4570 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4571 nl80211_mlme_mcgrp.id, gfp);
4572 return;
4574 nla_put_failure:
4575 genlmsg_cancel(msg, hdr);
4576 nlmsg_free(msg);
4579 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
4580 struct net_device *netdev, const u8 *addr,
4581 gfp_t gfp)
4583 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
4584 addr, gfp);
4587 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
4588 struct net_device *netdev, const u8 *addr,
4589 gfp_t gfp)
4591 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
4592 addr, gfp);
4595 void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
4596 struct net_device *netdev, const u8 *bssid,
4597 const u8 *req_ie, size_t req_ie_len,
4598 const u8 *resp_ie, size_t resp_ie_len,
4599 u16 status, gfp_t gfp)
4601 struct sk_buff *msg;
4602 void *hdr;
4604 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4605 if (!msg)
4606 return;
4608 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
4609 if (!hdr) {
4610 nlmsg_free(msg);
4611 return;
4614 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4615 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4616 if (bssid)
4617 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4618 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
4619 if (req_ie)
4620 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4621 if (resp_ie)
4622 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4624 if (genlmsg_end(msg, hdr) < 0) {
4625 nlmsg_free(msg);
4626 return;
4629 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4630 nl80211_mlme_mcgrp.id, gfp);
4631 return;
4633 nla_put_failure:
4634 genlmsg_cancel(msg, hdr);
4635 nlmsg_free(msg);
4639 void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
4640 struct net_device *netdev, const u8 *bssid,
4641 const u8 *req_ie, size_t req_ie_len,
4642 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
4644 struct sk_buff *msg;
4645 void *hdr;
4647 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4648 if (!msg)
4649 return;
4651 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
4652 if (!hdr) {
4653 nlmsg_free(msg);
4654 return;
4657 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4658 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4659 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4660 if (req_ie)
4661 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4662 if (resp_ie)
4663 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4665 if (genlmsg_end(msg, hdr) < 0) {
4666 nlmsg_free(msg);
4667 return;
4670 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4671 nl80211_mlme_mcgrp.id, gfp);
4672 return;
4674 nla_put_failure:
4675 genlmsg_cancel(msg, hdr);
4676 nlmsg_free(msg);
4680 void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
4681 struct net_device *netdev, u16 reason,
4682 const u8 *ie, size_t ie_len, bool from_ap)
4684 struct sk_buff *msg;
4685 void *hdr;
4687 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4688 if (!msg)
4689 return;
4691 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
4692 if (!hdr) {
4693 nlmsg_free(msg);
4694 return;
4697 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4698 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4699 if (from_ap && reason)
4700 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
4701 if (from_ap)
4702 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
4703 if (ie)
4704 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
4706 if (genlmsg_end(msg, hdr) < 0) {
4707 nlmsg_free(msg);
4708 return;
4711 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4712 nl80211_mlme_mcgrp.id, GFP_KERNEL);
4713 return;
4715 nla_put_failure:
4716 genlmsg_cancel(msg, hdr);
4717 nlmsg_free(msg);
4721 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
4722 struct net_device *netdev, const u8 *bssid,
4723 gfp_t gfp)
4725 struct sk_buff *msg;
4726 void *hdr;
4728 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4729 if (!msg)
4730 return;
4732 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
4733 if (!hdr) {
4734 nlmsg_free(msg);
4735 return;
4738 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4739 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4740 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4742 if (genlmsg_end(msg, hdr) < 0) {
4743 nlmsg_free(msg);
4744 return;
4747 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4748 nl80211_mlme_mcgrp.id, gfp);
4749 return;
4751 nla_put_failure:
4752 genlmsg_cancel(msg, hdr);
4753 nlmsg_free(msg);
4756 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
4757 struct net_device *netdev, const u8 *addr,
4758 enum nl80211_key_type key_type, int key_id,
4759 const u8 *tsc, gfp_t gfp)
4761 struct sk_buff *msg;
4762 void *hdr;
4764 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4765 if (!msg)
4766 return;
4768 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
4769 if (!hdr) {
4770 nlmsg_free(msg);
4771 return;
4774 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4775 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4776 if (addr)
4777 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4778 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
4779 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
4780 if (tsc)
4781 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
4783 if (genlmsg_end(msg, hdr) < 0) {
4784 nlmsg_free(msg);
4785 return;
4788 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4789 nl80211_mlme_mcgrp.id, gfp);
4790 return;
4792 nla_put_failure:
4793 genlmsg_cancel(msg, hdr);
4794 nlmsg_free(msg);
4797 void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
4798 struct ieee80211_channel *channel_before,
4799 struct ieee80211_channel *channel_after)
4801 struct sk_buff *msg;
4802 void *hdr;
4803 struct nlattr *nl_freq;
4805 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
4806 if (!msg)
4807 return;
4809 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
4810 if (!hdr) {
4811 nlmsg_free(msg);
4812 return;
4816 * Since we are applying the beacon hint to a wiphy we know its
4817 * wiphy_idx is valid
4819 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
4821 /* Before */
4822 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
4823 if (!nl_freq)
4824 goto nla_put_failure;
4825 if (nl80211_msg_put_channel(msg, channel_before))
4826 goto nla_put_failure;
4827 nla_nest_end(msg, nl_freq);
4829 /* After */
4830 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
4831 if (!nl_freq)
4832 goto nla_put_failure;
4833 if (nl80211_msg_put_channel(msg, channel_after))
4834 goto nla_put_failure;
4835 nla_nest_end(msg, nl_freq);
4837 if (genlmsg_end(msg, hdr) < 0) {
4838 nlmsg_free(msg);
4839 return;
4842 rcu_read_lock();
4843 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
4844 GFP_ATOMIC);
4845 rcu_read_unlock();
4847 return;
4849 nla_put_failure:
4850 genlmsg_cancel(msg, hdr);
4851 nlmsg_free(msg);
4854 /* initialisation/exit functions */
4856 int nl80211_init(void)
4858 int err;
4860 err = genl_register_family_with_ops(&nl80211_fam,
4861 nl80211_ops, ARRAY_SIZE(nl80211_ops));
4862 if (err)
4863 return err;
4865 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
4866 if (err)
4867 goto err_out;
4869 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
4870 if (err)
4871 goto err_out;
4873 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
4874 if (err)
4875 goto err_out;
4877 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
4878 if (err)
4879 goto err_out;
4881 #ifdef CONFIG_NL80211_TESTMODE
4882 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
4883 if (err)
4884 goto err_out;
4885 #endif
4887 return 0;
4888 err_out:
4889 genl_unregister_family(&nl80211_fam);
4890 return err;
4893 void nl80211_exit(void)
4895 genl_unregister_family(&nl80211_fam);